Simple:Press Plugin for WordPress Security Bypass and Arbitrary File Upload Vulnerabilities
BID:40345
Info
Simple:Press Plugin for WordPress Security Bypass and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 40345 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2010 12:00AM |
| Updated: | May 24 2010 12:00AM |
| Credit: | Simple:Press |
| Vulnerable: |
Simple:Press Simple:Press 4.1.2 Simple:Press Simple:Press 4.1 |
| Not Vulnerable: |
Simple:Press Simple:Press 4.1.3 |
Discussion
Simple:Press Plugin for WordPress Security Bypass and Arbitrary File Upload Vulnerabilities
The Simple:Press plugin for WordPress is prone to security-bypass and arbitrary-file-upload vulnerabilities.
Attackers can leverage these issues to bypass certain security restrictions and to upload and execute arbitrary code in the context of the application.
Versions prior to Simple:Press 4.1.3 are vulnerable.
The Simple:Press plugin for WordPress is prone to security-bypass and arbitrary-file-upload vulnerabilities.
Attackers can leverage these issues to bypass certain security restrictions and to upload and execute arbitrary code in the context of the application.
Versions prior to Simple:Press 4.1.3 are vulnerable.
Exploit / POC
Simple:Press Plugin for WordPress Security Bypass and Arbitrary File Upload Vulnerabilities
Attackers can exploit these issues with a web browser.
Attackers can exploit these issues with a web browser.
Solution / Fix
Simple:Press Plugin for WordPress Security Bypass and Arbitrary File Upload Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Simple:Press Plugin for WordPress Security Bypass and Arbitrary File Upload Vulnerabilities
References:
References:
- Post Install Notes (Simple:Press)
- Simple:Press Homepage (Simple:Press)
- SPF V4.1.3 Security Release Now Available (Simple:Press)