A vulnerability has been found in Spreadsheet(wpSS) WordPress plugin.
The SQL Injection vulnerability may allow an attacker to compromise your backend database and potentially your blog and web server.
A public exploit has been released on milw0rm by 1ten0.0net1.
The ’ss_id’ parameter inside ss_load.php is not correctly escaped before being passed to the database.
It was reported that all versions before 0.6 are vulnerable. The plugin homepage is currently not available. Therefore, we can’t prove that the version 0.61(released August ‘07) is indeed safe to use.
It is recommended that you disable this plugin until a fix has been verified.
This and several other sql holes have been plugged in version 0.62.
0.61 was vulnerable.
Thanks for the feedback Tim.
[…] Schadcode in die eigene Datanebank einzuschleusen. Eine entsprechende Warnugn gab es heute auf blogsecurity.net. Dort finden sich auch ein paar mehr Details zur Sicherheitslücke - leider keine Lösung […]
[…] Vía | BlogSecurity […]