WordPress 'get_allowed_mime_types()' Function Security Weakness
BID:62424
Info
WordPress 'get_allowed_mime_types()' Function Security Weakness
| Bugtraq ID: | 62424 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5738 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2013 12:00AM |
| Updated: | Sep 21 2013 12:13AM |
| Credit: | Reported by the vendor. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress 'get_allowed_mime_types()' Function Security Weakness
WordPress is prone to a security weakness.
An attacker can exploit this issue to conduct cross-site scripting attacks.
The issue is fixed in WordPress 3.6.1.
WordPress is prone to a security weakness.
An attacker can exploit this issue to conduct cross-site scripting attacks.
The issue is fixed in WordPress 3.6.1.
Exploit / POC
WordPress 'get_allowed_mime_types()' Function Security Weakness
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
WordPress 'get_allowed_mime_types()' Function Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress 'get_allowed_mime_types()' Function Security Weakness
References:
References: