WordPress wpDataTables Plugin Multiple Arbitrary File Upload Vulnerabilities
BID:71272
Info
WordPress wpDataTables Plugin Multiple Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 71272 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2014 12:00AM |
| Updated: | Dec 03 2014 12:55AM |
| Credit: | Claudio Viviani |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress wpDataTables Plugin Multiple Arbitrary File Upload Vulnerabilities
The wpDataTables plugin for WordPress is prone to multiple arbitrary file upload vulnerabilities.
An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
wpDataTables 1.5.3 and prior are vulnerable.
The wpDataTables plugin for WordPress is prone to multiple arbitrary file upload vulnerabilities.
An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
wpDataTables 1.5.3 and prior are vulnerable.
Exploit / POC
WordPress wpDataTables Plugin Multiple Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues using readily available tools.
The following exploit is available:
An attacker can exploit these issues using readily available tools.
The following exploit is available:
Solution / Fix
WordPress wpDataTables Plugin Multiple Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
WordPress wpDataTables Plugin Multiple Arbitrary File Upload Vulnerabilities
References:
References: