WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
BID:53855
Info
WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 53855 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3578 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2012 12:00AM |
| Updated: | Mar 19 2015 07:35AM |
| Credit: | Sammy FORGIT |
| Vulnerable: |
WordPress FCChat Widget 2.2.13 WordPress FCChat Widget 2.2.12 WordPress FCChat Widget 2.2.11 |
| Not Vulnerable: | |
Discussion
WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
WordPress FCChat Widget plugin is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
WordPress FCChat Widget plugin 2.2.12.2 through versions 2.2.13.1 are vulnerable.
WordPress FCChat Widget plugin is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
WordPress FCChat Widget plugin 2.2.12.2 through versions 2.2.13.1 are vulnerable.
Exploit / POC
WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
The following exploit is available:
Attackers can exploit this issue through a browser.
The following exploit is available:
Solution / Fix
WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
References:
References:
- WordPress FCChat Widget Homepage (WordPress)