WordPress Simple Login Log Plugin SQL Injection and HTML Injection Vulnerabilities
BID:57323
Info
WordPress Simple Login Log Plugin SQL Injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 57323 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2013 12:00AM |
| Updated: | Jan 15 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Simple Login Log Plugin SQL Injection and HTML Injection Vulnerabilities
The Simple Login Log plugin for WordPress is prone to an SQL-injection vulnerability and multiple HTML-injection vulnerabilities.
Exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
Simple Login Log 0.9.3 is vulnerable; prior versions may also be affected.
The Simple Login Log plugin for WordPress is prone to an SQL-injection vulnerability and multiple HTML-injection vulnerabilities.
Exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
Simple Login Log 0.9.3 is vulnerable; prior versions may also be affected.
Exploit / POC
WordPress Simple Login Log Plugin SQL Injection and HTML Injection Vulnerabilities
Attackers can exploit these issues using a browser.
Attackers can exploit these issues using a browser.
Solution / Fix
WordPress Simple Login Log Plugin SQL Injection and HTML Injection Vulnerabilities
Solution:
A vendor patch is available. Please see the references for more information.
Solution:
A vendor patch is available. Please see the references for more information.