Synopsis
The remote web server contains a PHP script that is affected by a SQL injection vulnerability.
Description
The remote host is running NextGEN Smooth Gallery, a third-party gallery viewer plugin for WordPress.
The version of this plugin installed on the remote host fails to sanitize input to the 'galleryID' parameter before using it in database queries.
Provided that PHP's 'magic_quotes_gpc' setting is not enabled, an unauthenticated, remote attacker can leverage this issue to manipulate database queries, resulting in the disclosure of sensitive information.
Solution
Unknown at this time.
Plugin Details
File Name: nextgen_smooth_gallery_galleryid_sqli.nasl
Supported Sensors: Nessus
Enable CGI Scanning: true
Vulnerability Information
CPE: cpe:/a:wordpress:wordpress
Required KB Items: installed_sw/WordPress, www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: Exploits are available
Exploited by Nessus: true
Vulnerability Publication Date: 8/3/2010
Reference Information
BID: 42156