WordPress Flexi Quote Rotator Plugin SQL Injection and Cross Site Request Forgery Vulnerabilities
BID:54656
Info
WordPress Flexi Quote Rotator Plugin SQL Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 54656 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2012 12:00AM |
| Updated: | Jul 24 2012 12:00AM |
| Credit: | Charlie Eriksen |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Flexi Quote Rotator Plugin SQL Injection and Cross Site Request Forgery Vulnerabilities
Flexi Quote Rotator plugin for WordPress is prone to a cross-site request-forgery vulnerability and an SQL-injection vulnerability.
Attackers may exploit these issues to compromise the application, access or modify data, exploit
vulnerabilities in the underlying database or to perform unauthorized actions by enticing a logged-in user to visit a malicious site.
Flexi Quote Rotator 0.9 is vulnerable; other versions may also be affected.
Flexi Quote Rotator plugin for WordPress is prone to a cross-site request-forgery vulnerability and an SQL-injection vulnerability.
Attackers may exploit these issues to compromise the application, access or modify data, exploit
vulnerabilities in the underlying database or to perform unauthorized actions by enticing a logged-in user to visit a malicious site.
Flexi Quote Rotator 0.9 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Flexi Quote Rotator Plugin SQL Injection and Cross Site Request Forgery Vulnerabilities
Attackers can use a browser to exploit the SQL-injection issue. To exploit the cross-site request-forgery issue, attackers must entice an unsuspecting victim to follow a malicious URI.
Attackers can use a browser to exploit the SQL-injection issue. To exploit the cross-site request-forgery issue, attackers must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
WordPress Flexi Quote Rotator Plugin SQL Injection and Cross Site Request Forgery Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
WordPress Flexi Quote Rotator Plugin SQL Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- 575843: Changeset for flexi-quote-rotator 0.9.2 (WordPress)
- Flexi Quote Rotator PLugin Changelog (WordPress)
- WordPress Flexi Quote Rotator Plugin Homepage (Stellar Web Works)