FireStats WordPress Plugin Multiple Cross Site Scripting and Authentication Bypass Vulnerabilities
BID:37099
Info
FireStats WordPress Plugin Multiple Cross Site Scripting and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 37099 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2008 12:00AM |
| Updated: | Nov 23 2009 11:05PM |
| Credit: | MustLive |
| Vulnerable: |
FireStats FireStats 1.0.2 |
| Not Vulnerable: | |
Discussion
FireStats WordPress Plugin Multiple Cross Site Scripting and Authentication Bypass Vulnerabilities
The FireStats plugin for WordPress is prone to multiple cross-site scripting vulnerabilities and an authentication-bypass vulnerability.
An attacker may leverage these issues to gain unauthorized access to the affected application and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
FireStats 1.0.2 is vulnerable; other versions may also be affected.
The FireStats plugin for WordPress is prone to multiple cross-site scripting vulnerabilities and an authentication-bypass vulnerability.
An attacker may leverage these issues to gain unauthorized access to the affected application and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
FireStats 1.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
FireStats WordPress Plugin Multiple Cross Site Scripting and Authentication Bypass Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following exploits are available:
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
The following exploits are available:
Solution / Fix
FireStats WordPress Plugin Multiple Cross Site Scripting and Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FireStats WordPress Plugin Multiple Cross Site Scripting and Authentication Bypass Vulnerabilities
References:
References:
- FireStats Homepage (FireStats)
- Multiple vulnerabilities in FireStats for WordPress (MustLive)
- Vulnerabilities in FireStats for WordPress (MustLive)