Release date:
Updated on:
Affected Systems:
WordPress Fb Survey Pro
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56595
WordPress is a Blog engine developed using the PHP language and MySQL database. you can create your own Blog on servers that support PHP and MySQL databases.
WordPress's Fb Survey Pro plug-in has the SQL injection vulnerability. Attackers can exploit this vulnerability to control applications, access or modify data, and exploit other vulnerabilities in lower-level databases.
<* Source: Chokri B..
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/wp-content/plugins/plugin-dir/timeline/index.php? Id = 1 & #39;-1 union select 1, 2, 4, 5
[SQL-Injection] --
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/