WordPress Answer My Question Plugin Multiple HTML Injection Vulnerabilities
BID:55601
Info
WordPress Answer My Question Plugin Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 55601 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2012 12:00AM |
| Updated: | Sep 19 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Answer My Question Plugin Multiple HTML Injection Vulnerabilities
The Answer My Question plugin for WordPress is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks may also be possible.
Answer My Question versions prior to 1.2 are vulnerable.
The Answer My Question plugin for WordPress is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks may also be possible.
Answer My Question versions prior to 1.2 are vulnerable.
Exploit / POC
WordPress Answer My Question Plugin Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues through a browser.
Attackers can exploit these issues through a browser.
Solution / Fix
WordPress Answer My Question Plugin Multiple HTML Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
WordPress Answer My Question Plugin Multiple HTML Injection Vulnerabilities
References:
References: