Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2008-0939
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0939

Description:
Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/40599

SREASON
  http://securityreason.com/securityalert/3693

SAID
  Secunia Advisory: SA28988

MISC
  http://weblogtoolscollection.com/archives/2008/02/21/photo-album-plugin-vulnerabilities/

MILW0RM
  http://www.milw0rm.com/exploits/5135

CONFIRM
  http://me.mywebsight.ws/web/wppa/

BUGTRAQ
  http://www.securityfocus.com/archive/1/488290

BID
  27832


Return to the previous page.