WordPress Relevanssi Plugin 'category_name' Parameter SQL Injection Vulnerability
BID:65960
Info
WordPress Relevanssi Plugin 'category_name' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 65960 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2014 12:00AM |
| Updated: | Mar 04 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
WordPress Relevanssi 3.0 |
| Not Vulnerable: |
WordPress Relevanssi 3.3 |
Discussion
WordPress Relevanssi Plugin 'category_name' Parameter SQL Injection Vulnerability
Relevanssi plugin for WordPress is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Versions prior to Relevanssi 3.3 are vulnerable.
Relevanssi plugin for WordPress is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Versions prior to Relevanssi 3.3 are vulnerable.
Exploit / POC
WordPress Relevanssi Plugin 'category_name' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
http://www.example.com/wordpress/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=[SQLi
Attackers can use a browser to exploit this issue.
http://www.example.com/wordpress/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=[SQLi
Solution / Fix
WordPress Relevanssi Plugin 'category_name' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress Relevanssi Plugin 'category_name' Parameter SQL Injection Vulnerability
References:
References:
- Relevanssi Homepage (WordPress)