vendor:
IndiaNIC FAQ Plugin
by:
m3tamantra
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: IndiaNIC FAQ Plugin
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:wordpress:faqs_manager:1.0
Platforms Tested: Apache/2.2.16 (Debian) PHP 5.3.3-7+squeeze14 with Suhosin-Patch (cli)
2013
WordPress IndiaNIC FAQ 1.0 Plugin Blind SQL Injection
The 'order' and 'orderby' parameter in the IndiaNIC FAQ 1.0 Plugin for WordPress is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting malicious SQL code into the 'order' or 'orderby' parameter.
Mitigation:
Update to a patched version of the plugin or remove the plugin from the WordPress installation.