WordPress Photocrati topic 'ecomm-sizes. php' SQL Injection Vulnerability
WordPress Photocrati topic 'ecomm-sizes. php' SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress Photocrati
Description:
Bugtraq id: 74854
CVE (CAN) ID: CVE-2015-2216
Photocrati is a topic of the WordPress website.
The Photocrati subject has the SQL injection vulnerability in the 'ecomm-sizes. php' implementation. Attackers can exploit this vulnerability to crack applications, access or modify data, and exploit other vulnerabilities in the database.
<* Source: Ayastar
*>
Test method:
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/wp-content/themes/?photocrati-path-theme#/ecomm-sizes.php? Prod_id = [SQL]
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/
This article permanently updates the link address: