WordPress Download Shortcode Plugin 'file' Parameter Arbitrary File Disclosure Vulnerability
BID:56097
Info
WordPress Download Shortcode Plugin 'file' Parameter Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 56097 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2012 12:00AM |
| Updated: | Oct 17 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Download Shortcode Plugin 'file' Parameter Arbitrary File Disclosure Vulnerability
The Download Shortcode plugin for WordPress is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Download Shortcode 0.1 is vulnerable; other versions may also be affected.
The Download Shortcode plugin for WordPress is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Download Shortcode 0.1 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Download Shortcode Plugin 'file' Parameter Arbitrary File Disclosure Vulnerability
Attackers can exploit this issue with a browser.
Attackers can exploit this issue with a browser.
Solution / Fix
WordPress Download Shortcode Plugin 'file' Parameter Arbitrary File Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
WordPress Download Shortcode Plugin 'file' Parameter Arbitrary File Disclosure Vulnerability
References:
References:
- Download Shortcode Homepage (WordPress)
- WordPress Homepage (WordPress)