Intrusion Prevention

PHP.phpWordPress.SQL.Injection

Description

It indicates a attacker attempted an SQL Injection attack against phpWordPress. phpWordPress contains multiple flaws that may allow an attacker to carry out SQL injection attacks. The flaws can be found in the "poll", "category", and "ctg" parameters in "index.php" which are not properly validated before being used in SQL queries. A successful exploit can allow an attacker to execute SQL queries against the database.

Affected Products

phpWordPress phpWordPress 3.0

Impact

Disclosure or Modification of sensitive data

Recommended Actions

Apply appropriate patch from the vendor or Upgrade to non-vulnerable version if available.