File tree Expand file tree Collapse file tree 1 file changed +57
-0
lines changed Expand file tree Collapse file tree 1 file changed +57
-0
lines changed Original file line number Diff line number Diff line change 2799927999 }
2800028000 ]
2800128001 },
28002+ "auxiliary_gather/wp_photo_gallery_sqli": {
28003+ "name": "WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)",
28004+ "fullname": "auxiliary/gather/wp_photo_gallery_sqli",
28005+ "aliases": [],
28006+ "rank": 300,
28007+ "disclosure_date": "2022-03-14",
28008+ "type": "auxiliary",
28009+ "author": [
28010+ "Krzysztof Zając",
28011+ "Valentin Lobstein",
28012+ "X3RX3S"
28013+ ],
28014+ "description": "The Photo Gallery by 10Web WordPress plugin <= 1.6.0 is vulnerable to\n unauthenticated SQL injection via the 'bwg_tag_id_bwg_thumbnails_0[]'\n parameter in admin-ajax.php (action=bwg_frontend_data).",
28015+ "references": [
28016+ "CVE-2022-0169",
28017+ "WPVDB-0b4d870f-eab8-4544-91f8-9c5f0538709c",
28018+ "URL-https://github.com/X3RX3SSec/CVE-2022-0169"
28019+ ],
28020+ "platform": "",
28021+ "arch": "",
28022+ "rport": 80,
28023+ "autofilter_ports": [
28024+ 80,
28025+ 8080,
28026+ 443,
28027+ 8000,
28028+ 8888,
28029+ 8880,
28030+ 8008,
28031+ 3000,
28032+ 8443
28033+ ],
28034+ "autofilter_services": [
28035+ "http",
28036+ "https"
28037+ ],
28038+ "targets": null,
28039+ "mod_time": "2025-07-16 22:04:13 +0000",
28040+ "path": "/modules/auxiliary/gather/wp_photo_gallery_sqli.rb",
28041+ "is_install_path": true,
28042+ "ref_name": "gather/wp_photo_gallery_sqli",
28043+ "check": true,
28044+ "post_auth": false,
28045+ "default_credential": false,
28046+ "notes": {
28047+ "Stability": [
28048+ "crash-safe"
28049+ ],
28050+ "SideEffects": [
28051+ "ioc-in-logs"
28052+ ],
28053+ "Reliability": []
28054+ },
28055+ "session_types": false,
28056+ "needs_cleanup": false,
28057+ "actions": []
28058+ },
2800228059 "auxiliary_gather/wp_ultimate_csv_importer_user_extract": {
2800328060 "name": "WordPress Ultimate CSV Importer User Table Extract",
2800428061 "fullname": "auxiliary/gather/wp_ultimate_csv_importer_user_extract",
You can’t perform that action at this time.
0 commit comments