PT-2023-9946 · Unknown · 404Like Plugin

Published

2023-03-20

·

Updated

2024-05-17

·

CVE-2012-10009

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 404like Plugin versions up to 1.0.2
Description A critical issue has been found in the 404like Plugin, affecting the checkPage function of the file 404Like.php. The manipulation of the searchWord argument leads to SQL injection, allowing remote attacks.
Recommendations For versions up to 1.0.2, upgrade to version 1.0.2 to address this issue. As a temporary workaround, consider restricting access to the checkPage function of the 404Like.php file until the upgrade is applied. Additionally, avoid using the searchWord argument in the affected function until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2012-10009

Affected Products

404Like Plugin