RULE(RULE ID:321815)

Rule General Information
Release Date: 2019-06-13
Rule Name: Wordpress Video Gallery SQL Injection Vulnerability (CVE-2015-2065)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: ExploitDB:36058
http://packetstormsecurity.com/files/130371/WordPress-Video-Gallery-2.7-SQL-Injection.html
SecurityFocusBID:74882
https://wordpress.org/plugins/contus-video-gallery/changelog/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://wordpress.org/plugins/contus-video-gallery/changelog/