WordPress Shopping Cart Plugin 'banneruploaderscript.php' Arbitrary File Upload Vulnerability
BID:71983
Info
WordPress Shopping Cart Plugin 'banneruploaderscript.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 71983 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9308 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2015 12:00AM |
| Updated: | Jan 09 2015 12:00AM |
| Credit: | Kacper Szurek |
| Vulnerable: |
Tribulant Software WordPress Shopping Cart 3.0.4 |
| Not Vulnerable: |
Tribulant Software WordPress Shopping Cart 3.0.9 |
Discussion
WordPress Shopping Cart Plugin 'banneruploaderscript.php' Arbitrary File Upload Vulnerability
The Shopping Cart plugin for WordPress is prone to an arbitrary file-upload vulnerability because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
WordPress Shopping Cart 3.0.4 is vulnerable; other versions may also be affected.
The Shopping Cart plugin for WordPress is prone to an arbitrary file-upload vulnerability because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
WordPress Shopping Cart 3.0.4 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Shopping Cart Plugin 'banneruploaderscript.php' Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser and readily available tools.
Attackers can exploit this issue through a browser and readily available tools.
Solution / Fix
WordPress Shopping Cart Plugin 'banneruploaderscript.php' Arbitrary File Upload Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
WordPress Shopping Cart Plugin 'banneruploaderscript.php' Arbitrary File Upload Vulnerability
References:
References:
- WordPress HomePage (WordPress)
- WordPress Shopping Cart Home Page (wordpress)
- WordPress Shopping Cart Vendor Page (tribulant)