vendor:
yolink Search
by:
Miroslav Stampar
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: yolink Search
Affected Version From: 1.1.2004
Affected Version To: 1.1.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:yolink_search
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
WordPress yolink Search plugin <= 1.1.4 SQL Injection Vulnerability
The vulnerability exists due to misusage of $wpdb->prepare() in the bulkcrawl.php script, which can be exploited to manipulate SQL queries by injecting arbitrary SQL code. This can be exploited to disclose the content of the database, to gain access to the administrative panel, etc.
Mitigation:
Upgrade to the latest version of the plugin.