WP-DBManager Arbitrary File Download Vulnerability and Cross Site Request Forgery Vulnerability
BID:47743
Info
WP-DBManager Arbitrary File Download Vulnerability and Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 47743 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2011 12:00AM |
| Updated: | May 06 2011 12:00AM |
| Credit: | Joakim Jardenberg, Jonas Nordstrom and Andreas Viklund |
| Vulnerable: |
Lester Chan WP-DBManager 2.6.1 |
| Not Vulnerable: |
Lester Chan WP-DBManager 2.6.2 |
Discussion
WP-DBManager Arbitrary File Download Vulnerability and Cross Site Request Forgery Vulnerability
WP-DBManager is prone to an arbitrary download vulnerability and a cross-site request-forgery vulnerability.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access, and gain access to sensitive information. Other attacks are also possible.
WP-DBManager is prone to an arbitrary download vulnerability and a cross-site request-forgery vulnerability.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access, and gain access to sensitive information. Other attacks are also possible.
Exploit / POC
WP-DBManager Arbitrary File Download Vulnerability and Cross Site Request Forgery Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
WP-DBManager Arbitrary File Download Vulnerability and Cross Site Request Forgery Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for details.
Solution:
The vendor released an update to address this issue. Please see the references for details.
References
WP-DBManager Arbitrary File Download Vulnerability and Cross Site Request Forgery Vulnerability
References:
References:
- WordPress Homepage (WordPress)
- WP-DBManager Release Notes (Lester Chan)