WordPress Media File Renamer Plugin Multiple HTML Injection Vulnerabilities
BID:65715
Info
WordPress Media File Renamer Plugin Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 65715 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2040 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2014 12:00AM |
| Updated: | Feb 20 2014 12:00AM |
| Credit: | Larry W. Cashdollar |
| Vulnerable: |
WordPress Media File Renamer 1.7 |
| Not Vulnerable: | |
Discussion
WordPress Media File Renamer Plugin Multiple HTML Injection Vulnerabilities
Media File Renamer plugin for WordPress is prone to multiple HTML-injection vulnerabilities.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Media File Renamer 1.7.0 is vulnerable; other versions may also be affected.
Media File Renamer plugin for WordPress is prone to multiple HTML-injection vulnerabilities.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Media File Renamer 1.7.0 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Media File Renamer Plugin Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues using browser.
Attackers can exploit these issues using browser.