WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
BID:37100
Info
WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 37100 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4168 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2009 12:00AM |
| Updated: | Sep 02 2014 12:14AM |
| Credit: | MustLive |
| Vulnerable: |
Yannick Lejeune Tumulus 0 WP-Cumulus WP-Cumulus 1.22 WP-Cumulus WP-Cumulus 1.21 WP-Cumulus WP-Cumulus 1.20 WP-Cumulus WP-Cumulus 1.19 WP-Cumulus WP-Cumulus 1.18 WP-Cumulus WP-Cumulus 1.17 WP-Cumulus WP-Cumulus 1.16 WP-Cumulus WP-Cumulus 1.15 WP-Cumulus WP-Cumulus 1.14 WP-Cumulus WP-Cumulus 1.13 WP-Cumulus WP-Cumulus 1.12 WP-Cumulus WP-Cumulus 1.11 WP-Cumulus WP-Cumulus 1.1 WP-Cumulus WP-Cumulus 1.05 WP-Cumulus WP-Cumulus 1.04 WP-Cumulus WP-Cumulus 1.03 WP-Cumulus WP-Cumulus 1.02 WP-Cumulus WP-Cumulus 1.01 WP-Cumulus WP-Cumulus 1.00 eZ publish eZ Flash Tag Cloud 1.0 BlogEngine.NET Cumulus widget 0 |
| Not Vulnerable: |
WP-Cumulus WP-Cumulus 1.23 eZ publish eZ Flash Tag Cloud 1.1 |
Discussion
WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
The WP-Cumulus plugin for WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to WP-Cumulus 1.23 are vulnerable.
The WP-Cumulus plugin for WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to WP-Cumulus 1.23 are vulnerable.
Exploit / POC
WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
Solution / Fix
WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
Solution:
A vendor update is available. Please contact the vendor for details.
Solution:
A vendor update is available. Please contact the vendor for details.
References
WordPress WP-Cumulus Plugin 'tagcloud.swf' Cross-Site Scripting Vulnerability
References:
References:
- BlogEngine.net Cumulus widget vulnearbility (MustLive)
- Email Newsletter plugin Homepage (WordPress)
- Flash tag cloud v1.1 : security update (eZ Publish)
- Tumulus (Yannick Lejeune)
- Vulnerability in WP-Cumulus for WordPress (MustLive)
- WP-Cumulus Product Page (WP-Cumulus)
- WP-Cumulus updated to address yet another security issue (Roy)
- Vulnerabilities in plugins for WordPress ('MustLive'
) - Vulnerabilities in WP-Cumulus for WordPress ("MustLive"
)