WordPress Plugin Vulnerabilities

NewStatPress < 1.0.6 - SQL Injection

Description

The Search functionality is susceptible to a SQL Injection attack due to usage of user input without sanitation.

In particular, at line 98 of 'includes/nsp_search.php'.

Utilising a specially crafted SQL query, we can trigger disclosure of user hashes through an IMG tag as the data channel.

Proof of Concept

Affects Plugins

Fixed in 1.0.6

References

Miscellaneous

Submitter
James Hooker
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-07-07 (about 10 years ago)
Added
2015-07-07 (about 10 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other