PT-2014-6340 · WordPress · Gallery Objects
Published
2014-08-12
·
Updated
2015-09-08
·
CVE-2014-5201
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gallery Objects plugin version 0.4 for WordPress
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the
viewid parameter in a go view object action to the /wp-admin/admin-ajax.php API endpoint.Recommendations
For Gallery Objects plugin version 0.4, consider disabling the
go view object action or restricting access to the /wp-admin/admin-ajax.php API endpoint until a patch is available. Avoid using the viewid parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gallery Objects