NextGEN Smooth Gallery Plugin for WordPress 'galleryID' Parameter SQL Injection

medium Nessus Plugin ID 49118

Synopsis

The remote web server contains a PHP script that is affected by a SQL injection vulnerability.

Description

The remote host is running NextGEN Smooth Gallery, a third-party gallery viewer plugin for WordPress.

The version of this plugin installed on the remote host fails to sanitize input to the 'galleryID' parameter before using it in database queries.

Provided that PHP's 'magic_quotes_gpc' setting is not enabled, an unauthenticated, remote attacker can leverage this issue to manipulate database queries, resulting in the disclosure of sensitive information.

Solution

Unknown at this time.

Plugin Details

Severity: Medium

ID: 49118

File Name: nextgen_smooth_gallery_galleryid_sqli.nasl

Version: 1.10

Type: remote

Family: CGI abuses

Published: 9/7/2010

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:wordpress:wordpress

Required KB Items: installed_sw/WordPress, www/PHP

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 8/3/2010

Reference Information

BID: 42156