CVE-2015-1055: SQL Injection
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the orderby parameter in a GalleryBox action to wp-admin/admin-ajax.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1055?
CVE-2015-1055 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2015-1055?
To fix CVE-2015-1055, update the Photo Gallery plugin to the latest version that addresses this SQL injection vulnerability.
Which version of the Photo Gallery plugin is affected by CVE-2015-1055?
CVE-2015-1055 specifically affects version 1.2.7 of the Photo Gallery plugin for WordPress.
Can CVE-2015-1055 be exploited without authentication?
Yes, CVE-2015-1055 can be exploited by unauthenticated remote attackers, making it particularly dangerous.
What are the potential impacts of exploiting CVE-2015-1055?
Exploiting CVE-2015-1055 can lead to unauthorized access to the database, data manipulation, and leakage of sensitive information.