vendor:
Traffic Analyzer
by:
Dan King
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Traffic Analyzer
Affected Version From: 3.4.2002
Affected Version To: 3.4.2002
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 14.10 with Mysql and Wordpress 4.11
2015
WordPress plugin ‘Traffic Analyzer’ Blind SQL Injection
The Wordpress plugin 'Traffic Analyzer' is vulnerable to a blind SQL injection vulnerability. The application does not properly validate input from the 'Referer' HTTP header value, which could allow a remote attacker to access the database with the privleges configured by Wordpress. This could also lead to the attack gaining remote access to the webservers filesystem and further compromise the system hosting the Wordpress installation.
Mitigation:
The vendor has released a patch for this vulnerability.