SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WordPress plugin Photo Gallery SQL Injection 3

Category: WEB-ATTACKS      

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.


Relevant Information