WP Super Cache Plugin for WordPress Remote PHP Code Execution Vulnerability
BID:59493
Info
WP Super Cache Plugin for WordPress Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 59493 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2013 12:00AM |
| Updated: | Apr 25 2013 12:00AM |
| Credit: | kisscsaby |
| Vulnerable: |
WordPress WP Super Cache 1.3.1 |
| Not Vulnerable: |
WordPress WP Super Cache 1.3.2 |
Discussion
WP Super Cache Plugin for WordPress Remote PHP Code Execution Vulnerability
The WP Super Cache plugin for WordPress is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected web server process.
Versions prior to WP Super Cache 1.3.2 are vulnerable.
The WP Super Cache plugin for WordPress is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected web server process.
Versions prior to WP Super Cache 1.3.2 are vulnerable.
Exploit / POC
WP Super Cache Plugin for WordPress Remote PHP Code Execution Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
WP Super Cache Plugin for WordPress Remote PHP Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.