vendor:
Olimometer Plugin for WordPress
by:
TAD GROUP
5.5
CVSS
MEDIUM
Sql Injection
89
CWE
Product Name: Olimometer Plugin for WordPress
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Debian 8
2016
Olimometer Plugin for WordPress – Sql Injection
Using GET SQL Method with the 'olimometer_id' parameter, we were able to get the database name from the EXAMPLE.COM website. By further running SQL Map using different arguments, we would be able to get the complete database, including usernames and passwords if there are such.
Mitigation:
Apply the latest patch or update the Olimometer Plugin for WordPress to a non-vulnerable version.