Update CVE-2016-10940.yaml

patch-1
Prince Chaddha 2022-02-03 01:24:10 +05:30 committed by GitHub
parent 7c9b7017d2
commit 61ba3a55e4
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 3 additions and 1 deletions

View File

@ -7,6 +7,7 @@ info:
description: The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
reference:
- https://wpscan.com/vulnerability/c0cbd314-0f4f-47db-911d-9b2e974bd0f6
- https://lenonleite.com.br/en/2016/12/16/zm-gallery-1-plugin-wordpress-blind-injection/
- https://nvd.nist.gov/vuln/detail/CVE-2016-10940
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
@ -39,6 +40,7 @@ requests:
- "ZM Gallery Plugin"
- "XPATH syntax error"
- "EXTRACTVALUE("
condition: and
- type: status
status: