|
Description
|
|
A weakness and a vulnerability have been discovered in the Google Maps Via Store Locator Plus plugin for WordPress, which can be exploited by malicious people to disclose system information and conduct SQL injection attacks.
1) An error exists due to the application displaying the installation path in debug output when accessing wp-content/plugins/store-locator-le/core/load_wp_config.php.
2) Input passed via the "query" parameter to /wp-content/plugins/store-locator-le/downloadcsv.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The weakness and vulnerability are confirmed in version 3.0.1. Other versions may also be affected.
|