漏洞标题
404like Plugin 404Like.php 检查页面SQL注入
漏洞描述信息
在WordPress的404like Plugin版本1.0.2及以下发现了一个漏洞,已被评为严重。受影响的是404Like.php文件中的checkPage函数。操纵searchWord参数会导致SQL注入。攻击可以远程发动。升级到版本1.0.2可以解决这个问题。补丁的名称是2c4b589d27554910ab1fd104ddbec9331b540f7f。建议升级受影响的组件。此漏洞的标识符为VDB-223404。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
404like Plugin 404Like.php checkPage sql injection
漏洞描述信息
A vulnerability was found in 404like Plugin up to 1.0.2 on WordPress. It has been classified as critical. Affected is the function checkPage of the file 404Like.php. The manipulation of the argument searchWord leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 1.0.2 is able to address this issue. The name of the patch is 2c4b589d27554910ab1fd104ddbec9331b540f7f. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-223404.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
WordPress Plugin 404like SQL注入漏洞
漏洞描述信息
WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress Plugin 404like 1.0.2及之前版本存在SQL注入漏洞,该漏洞源于文件404Like.php的函数checkPage存在问题,对参数searchWord的操作会导致sql注入。
CVSS信息
N/A
漏洞类别
SQL注入