WordPress FireStorm Professional Real Estate Plugin Multiple SQL Injection Vulnerabilities
17 Dec. 2012
Summary
The FireStorm Professional Real Estate plugin for WordPress is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Credit:
The information has been provided by Charlie Eriksen< /B>.
Vulnerable Systems:
* WordPress FireStorm Professional Real Estate 2.05.01
FireStorm Professional Real Estate plugin for WordPress is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the search.php script using the ProvinceID and CountryID parameters, which could allow the attacker to view, add, modify or delete information in the back-end database.