First published: Mon Feb 22 2010(Updated: )
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Copperleaf Photolog | =0.16 | |
WordPress | ||
All of | ||
Copperleaf Photolog | =0.16 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-0673 is classified as high due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2010-0673, update the Copperleaf Photolog plugin to the latest version or apply any available patches.
CVE-2010-0673 affects Copperleaf Photolog plugin version 0.16 and possibly earlier versions when used with WordPress.
CVE-2010-0673 is an SQL injection vulnerability which allows attackers to manipulate database queries.
Yes, attackers can exploit CVE-2010-0673 remotely without the need for authentication.