vendor:
Facebook Survey Pro Plugin
by:
Vulnerability Laboratory Research Team
8,5
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Facebook Survey Pro Plugin
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Wordpress
2012
WordPress Facebook Survey v1 – SQL Injection Vulnerability
A blind SQL Injection vulnerability is detected in the commercial Wordpress Facebook Survey Pro Plugin. The vulnerability allows an attacker (remote) or local low privileged user account to execute a SQL commands on the affected application dbms. The blind sql injection vulnerability is located in index.php file (timeline module) with the bound vulnerable id parameter. Successful exploitation of the vulnerability results in dbms & application compromise. Exploitation requires no user interaction & without privileged application user account.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable id parameter.