WordPress Age Verification plugin 'redirect_to' Parameter URI Redirection Vulnerability
BID:51357
Info
WordPress Age Verification plugin 'redirect_to' Parameter URI Redirection Vulnerability
| Bugtraq ID: | 51357 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2012 12:00AM |
| Updated: | Jan 10 2012 12:00AM |
| Credit: | Gianluca Brindisi |
| Vulnerable: |
WordPress Age Verification plugin 0.4 |
| Not Vulnerable: | |
Discussion
WordPress Age Verification plugin 'redirect_to' Parameter URI Redirection Vulnerability
WordPress Age Verification plugin is prone to a URI-redirection vulnerability because the application fails to properly sanitize user-supplied input.
A successful exploit may aid in phishing attacks; other attacks are possible.
WordPress Age Verification plugin 0.4 and prior versions are vulnerable.
WordPress Age Verification plugin is prone to a URI-redirection vulnerability because the application fails to properly sanitize user-supplied input.
A successful exploit may aid in phishing attacks; other attacks are possible.
WordPress Age Verification plugin 0.4 and prior versions are vulnerable.
Exploit / POC
WordPress Age Verification plugin 'redirect_to' Parameter URI Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/wp-content/plugins/age-verification/age-verification.php?redirect_to=http%3A%2F%2Fwww.evil.com
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/wp-content/plugins/age-verification/age-verification.php?redirect_to=http%3A%2F%2Fwww.evil.com
Solution / Fix
WordPress Age Verification plugin 'redirect_to' Parameter URI Redirection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress Age Verification plugin 'redirect_to' Parameter URI Redirection Vulnerability
References:
References:
- WordPress Homepage (WordPress)