SQL injection vulnerability research and troubleshooting in Apptha WordPress Video Gallery plug-in for CMS WordPress
Автор: Pestrikov R.A.
Журнал: Вестник Пермского университета. Серия: Математика. Механика. Информатика @vestnik-psu-mmi
Рубрика: Информатика. Информационные системы
Статья в выпуске: 3 (42), 2018 года.
Бесплатный доступ
The article deals with the mechanisms for implementing SQL injection attacks, which lead to the violation of the integrity, confidentiality and availability of information stored in the database. As an example, a plug-in for the WordPress content management system was studied, in which the vulnerability was investigated and fixed, as it leads to a SQL injection. The article also gives some security recommendations for building dynamic SQL-queries.
Sql-инъекции, wordpress, sql injection, dynamic query, security, cybersecurity, vulnerable query
Короткий адрес: https://sciup.org/147245385
IDR: 147245385 | DOI: 10.17072/1993-0550-2018-3-124-128