Unprepared queries allow DB Injection Attack
-
Hello,
it’s possible for attackers to exploit unprepared queries inside the function “wp_session_cleanup” for a DB Injection attack. In Detail: A manipulated session key be used to execute arbitrary database queries.
Please release a fixed version.
Best.
Stefan
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘Unprepared queries allow DB Injection Attack’ is closed to new replies.