WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
BID:54128
Info
WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
| Bugtraq ID: | 54128 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2012 12:00AM |
| Updated: | Jun 21 2012 12:00AM |
| Credit: | Charlie Eriksen via Secunia |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
Mac Photo Gallery plugin for WordPress is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Mac Photo Gallery 2.8 is vulnerable; other versions may also be affected.
Mac Photo Gallery plugin for WordPress is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Mac Photo Gallery 2.8 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
References:
References:
- WordPress Homepage (WordPress)