vendor:
Gallery Objects
by:
Claudio Viviani
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Gallery Objects
Affected Version From: 0.4
Affected Version To: 0.4
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:gallery_objects:0.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7, Linux
2014
WordPress Gallery Objects 0.4 SQL Injection
WordPress Gallery Objects 0.4 is vulnerable to SQL injection. An attacker can exploit this vulnerability to inject malicious SQL queries in the application, allowing them to bypass authentication, access, modify and delete data in the back-end database.
Mitigation:
Update to the latest version of WordPress Gallery Objects 0.4