WordPress U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure Vulnerability
BID:49284
Info
WordPress U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure Vulnerability
| Bugtraq ID: | 49284 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2011 12:00AM |
| Updated: | Aug 23 2011 12:00AM |
| Credit: | Julio Potier |
| Vulnerable: |
Taehan Lee U BuddyPress Forum Attachment 1.1.1 |
| Not Vulnerable: |
Taehan Lee U BuddyPress Forum Attachment 1.1.2 |
Discussion
WordPress U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure Vulnerability
U BuddyPress Forum Attachment for WordPress is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the webserver process, which may aid in further attacks.
Versions prior to U BuddyPress Forum Attachment 1.1.2 are vulnerable.
U BuddyPress Forum Attachment for WordPress is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the webserver process, which may aid in further attacks.
Versions prior to U BuddyPress Forum Attachment 1.1.2 are vulnerable.
Exploit / POC
WordPress U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
WordPress U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
WordPress U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure Vulnerability
References:
References:
- U BuddyPress Forum Attachment Homepage (WordPress)