File tree Expand file tree Collapse file tree 1 file changed +57
-0
lines changed Expand file tree Collapse file tree 1 file changed +57
-0
lines changed Original file line number Diff line number Diff line change 27999
27999
}
28000
28000
]
28001
28001
},
28002
+ "auxiliary_gather/wp_photo_gallery_sqli": {
28003
+ "name": "WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)",
28004
+ "fullname": "auxiliary/gather/wp_photo_gallery_sqli",
28005
+ "aliases": [],
28006
+ "rank": 300,
28007
+ "disclosure_date": "2022-03-14",
28008
+ "type": "auxiliary",
28009
+ "author": [
28010
+ "Krzysztof Zając",
28011
+ "Valentin Lobstein",
28012
+ "X3RX3S"
28013
+ ],
28014
+ "description": "The Photo Gallery by 10Web WordPress plugin <= 1.6.0 is vulnerable to\n unauthenticated SQL injection via the 'bwg_tag_id_bwg_thumbnails_0[]'\n parameter in admin-ajax.php (action=bwg_frontend_data).",
28015
+ "references": [
28016
+ "CVE-2022-0169",
28017
+ "WPVDB-0b4d870f-eab8-4544-91f8-9c5f0538709c",
28018
+ "URL-https://github.com/X3RX3SSec/CVE-2022-0169"
28019
+ ],
28020
+ "platform": "",
28021
+ "arch": "",
28022
+ "rport": 80,
28023
+ "autofilter_ports": [
28024
+ 80,
28025
+ 8080,
28026
+ 443,
28027
+ 8000,
28028
+ 8888,
28029
+ 8880,
28030
+ 8008,
28031
+ 3000,
28032
+ 8443
28033
+ ],
28034
+ "autofilter_services": [
28035
+ "http",
28036
+ "https"
28037
+ ],
28038
+ "targets": null,
28039
+ "mod_time": "2025-07-16 22:04:13 +0000",
28040
+ "path": "/modules/auxiliary/gather/wp_photo_gallery_sqli.rb",
28041
+ "is_install_path": true,
28042
+ "ref_name": "gather/wp_photo_gallery_sqli",
28043
+ "check": true,
28044
+ "post_auth": false,
28045
+ "default_credential": false,
28046
+ "notes": {
28047
+ "Stability": [
28048
+ "crash-safe"
28049
+ ],
28050
+ "SideEffects": [
28051
+ "ioc-in-logs"
28052
+ ],
28053
+ "Reliability": []
28054
+ },
28055
+ "session_types": false,
28056
+ "needs_cleanup": false,
28057
+ "actions": []
28058
+ },
28002
28059
"auxiliary_gather/wp_ultimate_csv_importer_user_extract": {
28003
28060
"name": "WordPress Ultimate CSV Importer User Table Extract",
28004
28061
"fullname": "auxiliary/gather/wp_ultimate_csv_importer_user_extract",
You can’t perform that action at this time.
0 commit comments