Lucene search

K
wpvulndbLarry W. CashdollarWPVDB-ID:61727560-1055-45B6-82E8-6A118164996E
HistoryAug 22, 2015 - 12:00 a.m.

DukaPress <= 2.5.9 - Unauthenticated Blind SQL Injection

2015-08-2200:00:00
Larry W. Cashdollar
wpscan.com
8

0.002 Low

EPSS

Percentile

57.0%

The code in dukapress/download.php does not sanitize user input from $_GET[‘id’] before passing it to query() allowing SQL to be injected. The user is not required to be logged into WordPress in order to exploit this vulnerability.

CPENameOperatorVersion
dukapresslt2.5.9.1

0.002 Low

EPSS

Percentile

57.0%

Related for WPVDB-ID:61727560-1055-45B6-82E8-6A118164996E