WordPress Ad Manager Plugin 'track-click.php' Open Redirection Vulnerability
BID:71320
Info
WordPress Ad Manager Plugin 'track-click.php' Open Redirection Vulnerability
| Bugtraq ID: | 71320 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8754 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | Nov 25 2014 12:00AM |
| Credit: | Wang Jing |
| Vulnerable: |
codecanyon Ad Manager 1.1.2 |
| Not Vulnerable: | |
Discussion
WordPress Ad Manager Plugin 'track-click.php' Open Redirection Vulnerability
The Ad Manager plugin for WordPress is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to redirect a user to a potentially malicious site and gain elevated privileges in the context of the affected application.
Ad Manager 1.1.2 is vulnerable; other versions may also be affected.
The Ad Manager plugin for WordPress is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to redirect a user to a potentially malicious site and gain elevated privileges in the context of the affected application.
Ad Manager 1.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Ad Manager Plugin 'track-click.php' Open Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to following a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to following a malicious URI.
Solution / Fix
WordPress Ad Manager Plugin 'track-click.php' Open Redirection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
WordPress Ad Manager Plugin 'track-click.php' Open Redirection Vulnerability
References:
References:
- Ad Manager Homepage (Codecanyon)
- WordPress �??Ad-Manager Plugin�?� Dest Redirect Privilege Escalation (Tetraph)