WordPress WP Custom Pages Plugin 'url' Parameter Local File Disclosure Vulnerability
BID:47146
Info
WordPress WP Custom Pages Plugin 'url' Parameter Local File Disclosure Vulnerability
| Bugtraq ID: | 47146 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1669 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | John Leitch, AutoSec Tools |
| Vulnerable: |
WordPress WP Custom Pages 0.5.0.1 |
| Not Vulnerable: | |
Discussion
WordPress WP Custom Pages Plugin 'url' Parameter Local File Disclosure Vulnerability
WordPress WP Custom Pages plugin is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability may allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
WP Custom Pages versions 0.5.0.1 and prior are vulnerable.
WordPress WP Custom Pages plugin is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability may allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
WP Custom Pages versions 0.5.0.1 and prior are vulnerable.
Exploit / POC
WordPress WP Custom Pages Plugin 'url' Parameter Local File Disclosure Vulnerability
Attackers may exploit this issue through a browser.
The following example URI is available:
http://www.example.com/wordpress/wp-content/plugins/wp-custom-pages/wp-download.php?url=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini
Attackers may exploit this issue through a browser.
The following example URI is available:
http://www.example.com/wordpress/wp-content/plugins/wp-custom-pages/wp-download.php?url=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini
Solution / Fix
WordPress WP Custom Pages Plugin 'url' Parameter Local File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress WP Custom Pages Plugin 'url' Parameter Local File Disclosure Vulnerability
References:
References:
- Wordpress church_admin Plugin "id" Cross-Site Scripting Vulnerability (Sammy Forgit)
- WP Custom Pages Homepage (WordPress)
- WordPress WP Custom Pages 0.5.0.1 Local File Inclusion (AutoSec Tools)