Subscribe to Comments WordPress Plugin Unsubscribe Challenge Information Disclosure Vulnerability
BID:37104
Info
Subscribe to Comments WordPress Plugin Unsubscribe Challenge Information Disclosure Vulnerability
| Bugtraq ID: | 37104 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2006 12:00AM |
| Updated: | Nov 23 2009 11:25PM |
| Credit: | Steven J. Murdoch |
| Vulnerable: |
Mark Jaquith Subscribe to Comments 2.0.2 Mark Jaquith Subscribe to Comments 0 |
| Not Vulnerable: |
Mark Jaquith Subscribe to Comments 2.0.4 |
Discussion
Subscribe to Comments WordPress Plugin Unsubscribe Challenge Information Disclosure Vulnerability
The Subscribe to Comments plugin for WordPress is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Versions prior to Subscribe to Comments 2.0.4 are vulnerable.
The Subscribe to Comments plugin for WordPress is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Versions prior to Subscribe to Comments 2.0.4 are vulnerable.
Exploit / POC
Subscribe to Comments WordPress Plugin Unsubscribe Challenge Information Disclosure Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Subscribe to Comments WordPress Plugin Unsubscribe Challenge Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Subscribe to Comments WordPress Plugin Unsubscribe Challenge Information Disclosure Vulnerability
References:
References:
- Oracle attack on Wordpress (Steven J. Murdoch)
- Subscribe to Comments 2.0.4 (Mark Jaquith)
- Subscribe to Comments Homepage (Mark Jaquith)
- Wordpress church_admin Plugin "id" Cross-Site Scripting Vulnerability (Sammy Forgit)