vendor:
PureHTML
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PureHTML
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:purehtml:1.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
WordPress PureHTML plugin <= 1.0.0 SQL Injection Vulnerability
A SQL injection vulnerability exists in WordPress PureHTML plugin version 1.0.0 due to the misuse of $wpdb->prepare() function. An attacker can send a specially crafted POST request to the alter.php script with the action parameter set to delete and the id parameter set to -1' AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0)--%20, which will allow the attacker to execute arbitrary SQL commands.
Mitigation:
Ensure that user input is properly validated and filtered before being used in SQL queries.