WordPress Export To Text Plugin 'download' Parameter Remote File Include Vulnerability
BID:60181
Info
WordPress Export To Text Plugin 'download' Parameter Remote File Include Vulnerability
| Bugtraq ID: | 60181 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2013 12:00AM |
| Updated: | May 28 2013 12:00AM |
| Credit: | Charlie Eriksen via Secunia |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Export To Text Plugin 'download' Parameter Remote File Include Vulnerability
The Export To Text Plugin for WordPress is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Export To Text Plugin 2.2 is vulnerable; other versions may also be affected.
The Export To Text Plugin for WordPress is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Export To Text Plugin 2.2 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Export To Text Plugin 'download' Parameter Remote File Include Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
WordPress Export To Text Plugin 'download' Parameter Remote File Include Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
WordPress Export To Text Plugin 'download' Parameter Remote File Include Vulnerability
References:
References: