Release date:
Updated on: 2013-02-03
Affected Systems:
WordPress Poll Plugin 34.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57630
The WordPress Poll plug-in is a fully interactive voting system that supports single choice and multiple choice.
WordPress Poll 34.05 and earlier versions do not correctly verify the values of certain parameters, resulting in the SQL injection vulnerability.
1) wp-admin/admin-ajax.php (when "action" is set to "view_poll_result" or "submit_vote") the value of "poll_id" is not correctly verified;
2) wp-admin/admin-ajax.php (when "action" is set to "deletepoll", "editpoll", "update_answer", "delete_answer", "add_answer", "save_changes ", "view_poll_logs") the value of "pollid" is not verified correctly;
To successfully exploit these vulnerabilities, You need to obtain the "nonce" value.
<* Source: Marcela Benetrix
Link: http://secunia.com/advisories/51925/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/extend/plugins/cardoza-wordpress-poll/changelog/