WordPress Contus Video Gallery plugin SQL Injection Vulnerability
WordPress Contus Video Gallery plugin SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress Contus Video Gallery <= 2.7
Description:
WordPress Contus Video Gallery is the Video library plug-in on the WordPress site.
Contus Video Gallery 2.7 and earlier versions do not properly filter the content of the "vid" GET parameter in "wp-admin/admin-ajax.php", which allows attackers to inject arbitrary SQL code and manipulate SQL queries. To exploit this vulnerability, you must have Editor or higher permissions.
<* Source: fig
Link: http://secunia.com/advisories/64426/
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Contus Video Gallery:
Https://wordpress.org/plugins/contus-video-gallery/changelog/
Kradio Viviani:
Http://packetstormsecurity.org/files/131418/WordPress-Video-Gallery-2.8-SQL-Injection.html
This article permanently updates the link address: