WordPress Maps Marker Pro Plugin Multiple Unspecified Security Vulnerabilities
BID:66597
Info
WordPress Maps Marker Pro Plugin Multiple Unspecified Security Vulnerabilities
| Bugtraq ID: | 66597 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2014 12:00AM |
| Updated: | Apr 02 2014 12:00AM |
| Credit: | The City of Vienna |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Maps Marker Pro Plugin Multiple Unspecified Security Vulnerabilities
The Maps Marker Pro plugin for WordPress is prone to multiple security vulnerabilities, including:
1. An unspecified HTML-injection vulnerability
2. An unspecified arbitrary file-upload vulnerability
3. An unspecified directory-traversal vulnerability
Attackers can exploit these issues to access arbitrary files that contain sensitive information, upload arbitrary files to the affected computer; this can result in arbitrary code execution, attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
Versions prior to Maps Marker Pro 1.5.8 are vulnerable.
The Maps Marker Pro plugin for WordPress is prone to multiple security vulnerabilities, including:
1. An unspecified HTML-injection vulnerability
2. An unspecified arbitrary file-upload vulnerability
3. An unspecified directory-traversal vulnerability
Attackers can exploit these issues to access arbitrary files that contain sensitive information, upload arbitrary files to the affected computer; this can result in arbitrary code execution, attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
Versions prior to Maps Marker Pro 1.5.8 are vulnerable.
Exploit / POC
WordPress Maps Marker Pro Plugin Multiple Unspecified Security Vulnerabilities
An attacker can exploit these issues using a web browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI
An attacker can exploit these issues using a web browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI
References
WordPress Maps Marker Pro Plugin Multiple Unspecified Security Vulnerabilities
References:
References: