CVEs Blog | G5 Cyber Security

CVE-2015-1055 – SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPre

SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1055

Reference (s):

Exit mobile version