WordPress WP Symposium plugin 'get _ album_item.php 'SQL Injection Vulnerability
WordPress WP Symposium plugin 'get _ album_item.php 'SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress WP Symposium <15.8
WordPress WP Symposium
Description:
Bugtraq id: 76499
CVE (CAN) ID: CVE-2015-6522
WordPress WP Symposium plug-in is a network plug-in that adds social functions.
In versions earlier than WordPress WP Symposium Plug-In 15.8, the 'get _ album_item.php 'implementation has the SQL injection vulnerability. attackers can execute arbitrary SQL commands by using the size parameter of get_album_item.php.
<* Source: PizzaHatHacker
Link: https://www.exploit-db.com/exploits/37824/
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wpsymposium.com/
This article permanently updates the link address: