Is there any truth to this claim about the Toolbox theme? http://osvdb.org/show/osvdb/88293
“Toolbox Theme for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /wp-content/Themes/toolbox/include/flyer.php script not properly sanitizing user-supplied input to the ‘mls’ parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.”
Can anyone elaborate on this, whether it’s been fixed, or how one can patch it?
- The topic ‘SQL Injection Vulnerability’ is closed to new replies.