WordPress Lazyest Gallery Plugin 'EXIF' Tag HTML Injection Vulnerability
BID:66756
Info
WordPress Lazyest Gallery Plugin 'EXIF' Tag HTML Injection Vulnerability
| Bugtraq ID: | 66756 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2333 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2014 12:00AM |
| Updated: | Apr 10 2014 12:00AM |
| Credit: | Daniel Marques @0xc0da |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Lazyest Gallery Plugin 'EXIF' Tag HTML Injection Vulnerability
Lazyest Gallery Plugin for WordPress is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
WordPress Lazyest Gallery Plugin prior to 1.1.21 are vulnerable.
Lazyest Gallery Plugin for WordPress is prone to an HTML-injection vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
WordPress Lazyest Gallery Plugin prior to 1.1.21 are vulnerable.
Exploit / POC
WordPress Lazyest Gallery Plugin 'EXIF' Tag HTML Injection Vulnerability
Attackers can exploit these issues using browser.
Attackers can exploit these issues using browser.
Solution / Fix
WordPress Lazyest Gallery Plugin 'EXIF' Tag HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WordPress Lazyest Gallery Plugin 'EXIF' Tag HTML Injection Vulnerability
References:
References:
- Lazyest Gallery Homepage (Brimosoft)
- Lazyest Gallery WordPress Plugin (Brimosoft)