vendor:
WP DS FAQ plugin
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WP DS FAQ plugin
Affected Version From: 1.3.2002
Affected Version To: 1.3.2002
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wp_ds_faq
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
WordPress WP DS FAQ plugin <= 1.3.2 SQL Injection Vulnerability
The vulnerability exists due to insufficient sanitization of user-supplied input in 'id' parameter of 'delete_faqbook' action in 'ajax.php' script. A remote attacker can send a specially crafted request to the vulnerable script and execute arbitrary SQL commands in application's database. This can be exploited to bypass certain security restrictions, read/modify data in the database, compromise the system, etc.
Mitigation:
Update to version 1.3.3 or later.