Release date:
Updated on:
Affected Systems:
WordPress search-everything <= 7.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65765
The Search Everything plug-in can enhance the default Search function of WordPress.
Search Everything 7.0.2 and other versions do not properly filter the "s" parameter value in index. php. Malicious users can exploit this vulnerability to operate SQL queries by injecting arbitrary SQL code.
<* Source: vendor
Link: http://secunia.com/advisories/56820/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/plugins/search-everything/
Http://wordpress.org/plugins/search-everything/changelog/