CVE-2015-1393: SQL Injection
Published Feb 2, 2015
·Updated
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the ascordesc parameter in a create gallery request in the galleriesbwg page to wp-admin/admin.php.
Affected Software
1 affected component
10web Photo Gallery Wordpress<=1.2.9
Event History
Feb 2, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1393?
CVE-2015-1393 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2015-1393?
To mitigate CVE-2015-1393, upgrade the Photo Gallery plugin to version 1.2.11 or later.
3
Who is affected by CVE-2015-1393?
CVE-2015-1393 affects remote authenticated users of the Photo Gallery plugin for WordPress versions prior to 1.2.11.
4
What type of vulnerability is CVE-2015-1393?
CVE-2015-1393 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
When was CVE-2015-1393 published?
CVE-2015-1393 was published in 2015, identifying a critical security risk in the Photo Gallery plugin.