WordPress iMember360 Plugin Multiple Security Vulnerabilities
BID:67088
Info
WordPress iMember360 Plugin Multiple Security Vulnerabilities
| Bugtraq ID: | 67088 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3842 CVE-2014-3849 CVE-2014-3848 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2014 12:00AM |
| Updated: | May 29 2014 03:55AM |
| Credit: | Everett Griffiths |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress iMember360 Plugin Multiple Security Vulnerabilities
WordPress iMember360 plugin is prone to multiple security vulnerabilities.
An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, unauthorized access or to execute arbitrary code. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
iMember360 versions 3.8.012 through 3.9.001 are vulnerable.
WordPress iMember360 plugin is prone to multiple security vulnerabilities.
An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, unauthorized access or to execute arbitrary code. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
iMember360 versions 3.8.012 through 3.9.001 are vulnerable.
Exploit / POC
WordPress iMember360 Plugin Multiple Security Vulnerabilities
An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, unauthorized access or to execute arbitrary code. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, unauthorized access or to execute arbitrary code. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Solution / Fix
WordPress iMember360 Plugin Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress iMember360 Plugin Multiple Security Vulnerabilities
References:
References: