Subscribe to Comments WordPress Plugin Multiple Unspecified Input Validation Vulnerabilities
BID:37113
Info
Subscribe to Comments WordPress Plugin Multiple Unspecified Input Validation Vulnerabilities
| Bugtraq ID: | 37113 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2009 12:00AM |
| Updated: | Nov 24 2009 11:05PM |
| Credit: | MustLive |
| Vulnerable: |
Mark Jaquith Subscribe to Comments 2.0.8 Mark Jaquith Subscribe to Comments 2.0.4 Mark Jaquith Subscribe to Comments 2.0.2 Mark Jaquith Subscribe to Comments 2.1 Mark Jaquith Subscribe to Comments 0 |
| Not Vulnerable: | |
Discussion
Subscribe to Comments WordPress Plugin Multiple Unspecified Input Validation Vulnerabilities
The Subscribe to Comments plugin for WordPress is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Very few details are available. We will update this BID as more information emerges.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials or compromise the application. Other attacks are possible.
The Subscribe to Comments plugin for WordPress is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Very few details are available. We will update this BID as more information emerges.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials or compromise the application. Other attacks are possible.
Exploit / POC
Subscribe to Comments WordPress Plugin Multiple Unspecified Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.
Solution / Fix
Subscribe to Comments WordPress Plugin Multiple Unspecified Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Subscribe to Comments WordPress Plugin Multiple Unspecified Input Validation Vulnerabilities
References:
References:
- Subscribe to Comments Homepage (Mark Jaquith)
- Vulnerability in Subscribe To Comments for WordPress (MustLive)
- Vulnerabilities in plugins for WordPress ('MustLive'
)