WordPress s2Member Local File Disclosure Vulnerability
BID:49624
Info
WordPress s2Member Local File Disclosure Vulnerability
| Bugtraq ID: | 49624 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2011 12:00AM |
| Updated: | Sep 14 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
WebSharks s2Member 110812 |
| Not Vulnerable: |
WebSharks s2Member 110813 |
Discussion
WordPress s2Member Local File Disclosure Vulnerability
The s2Member plug-in for WordPress is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
s2Member 110812 is vulnerable; other versions may also be affected.
The s2Member plug-in for WordPress is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
Exploiting this vulnerability could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
s2Member 110812 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress s2Member Local File Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
WordPress s2Member Local File Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WordPress s2Member Local File Disclosure Vulnerability
References:
References:
- s2Member Homepage (WebSharks)
- WordPress Home Page (WordPress)
- Change Log (WordPress)