Portfolio Gallery Plugin ଯେପର୍ଯ୍ୟନ୍ତ 1.1.8 ଅନ୍ WordPress SQL ଇଞ୍ଜେକ୍ସନ

Rakkoon nageenyaa kan ଜଟିଳ jedhamuun beekamu Portfolio Gallery Plugin ଯେପର୍ଯ୍ୟନ୍ତ 1.1.8 irratti WordPress keessatti argameera. Kan miidhamte is hojii hin beekamne. Hojii jijjiirraa gara SQL ଇଞ୍ଜେକ୍ସନ geessa. CWE fayyadamuun rakkoo ibsuun gara CWE-89 geessa. Dadhabbii kana yeroo 09/19/2014 maxxanfameera akka 58ed88243e17df766036f4857041edaf358076d3. Odeeffannoon kun buufachuuf github.com irratti qoodameera. Dogoggorri kun akka CVE-2014-125101tti beekama. Yaaliin weeraraa fageenya irraa jalqabamuu ni danda'a. Faayidaaleen teeknikaa hin jiru. Meeshaa balaa kana fayyadamuuf hin jiru. Amma, gatii ammee exploit might be approx. USD $0-$5k ta'uu danda'a. Akka ଅପରିଭାଷିତ jedhamee ibsameera. Akka 0-daytti, gatii daldalaa dhoksaa tilmaamame $0-$5k ta'ee ture. Beekamtii paachii kanaa 58ed88243e17df766036f4857041edaf358076d3 dha. Sirreeffamni rakkoo github.com irratti buufachuuf qophaa’eera. Qabiyyee miidhamte fooyyessuuf gorsa ni kennama. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

2 ଆଡାପ୍ଟେସନ୍ · 46 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
05/27/2023 09:58 AM
ଅଦ୍ୟତନ 1/1
06/21/2023 01:18 PM
software_namePortfolio Gallery PluginPortfolio Gallery Plugin
software_version<=1.1.8<=1.1.8
software_platformWordPressWordPress
vulnerability_cweCWE-89 (SQL ଇଞ୍ଜେକ୍ସନ)CWE-89 (SQL ଇଞ୍ଜେକ୍ସନ)
vulnerability_risk22
cvss3_vuldb_avNN
cvss3_vuldb_acLL
cvss3_vuldb_uiNN
cvss3_vuldb_sUU
cvss3_vuldb_cLL
cvss3_vuldb_iLL
cvss3_vuldb_aLL
cvss3_vuldb_rlOO
cvss3_vuldb_rcCC
advisory_date1411077600 (09/19/2014)1411077600 (09/19/2014)
advisory_identifier58ed88243e17df766036f4857041edaf358076d358ed88243e17df766036f4857041edaf358076d3
advisory_urlhttps://github.com/wp-plugins/portfolio-gallery/commit/58ed88243e17df766036f4857041edaf358076d3https://github.com/wp-plugins/portfolio-gallery/commit/58ed88243e17df766036f4857041edaf358076d3
countermeasure_nameଅପଗ୍ରେଡ୍ କରନ୍ତୁଅପଗ୍ରେଡ୍ କରନ୍ତୁ
countermeasure_date1411077600 (09/19/2014)1411077600 (09/19/2014)
upgrade_version1.1.91.1.9
patch_name58ed88243e17df766036f4857041edaf358076d358ed88243e17df766036f4857041edaf358076d3
countermeasure_patch_urlhttps://github.com/wp-plugins/portfolio-gallery/commit/58ed88243e17df766036f4857041edaf358076d3https://github.com/wp-plugins/portfolio-gallery/commit/58ed88243e17df766036f4857041edaf358076d3
countermeasure_advisoryquoteSQL Injection bag has fixed in Portfolio GallerySQL Injection bag has fixed in Portfolio Gallery
source_cveCVE-2014-125101CVE-2014-125101
cna_responsibleVulDBVulDB
software_typePhoto Gallery SoftwarePhoto Gallery Software
cvss2_vuldb_avNN
cvss2_vuldb_acLL
cvss2_vuldb_ciPP
cvss2_vuldb_iiPP
cvss2_vuldb_aiPP
cvss2_vuldb_rcCC
cvss2_vuldb_rlOFOF
cvss2_vuldb_auSS
cvss2_vuldb_eNDND
cvss3_vuldb_prLL
cvss3_vuldb_eXX
cvss2_vuldb_basescore6.56.5
cvss2_vuldb_tempscore5.75.7
cvss3_vuldb_basescore6.36.3
cvss3_vuldb_tempscore6.06.0
cvss3_meta_basescore6.36.3
cvss3_meta_tempscore6.06.0
price_0day$0-$5k$0-$5k
cve_assigned1685138400 (05/27/2023)
cve_nvd_summaryA vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 is able to address this issue. The name of the patch is 58ed88243e17df766036f4857041edaf358076d3. It is recommended to upgrade the affected component. The identifier VDB-230085 was assigned to this vulnerability.

Want to stay up to date on a daily basis?

Enable the mail alert feature now!