Wordpress Remote PHP File Include Vulnerability
BID:7785
Info
Wordpress Remote PHP File Include Vulnerability
| Bugtraq ID: | 7785 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-1599 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2003 12:00AM |
| Updated: | Jan 06 2012 10:00PM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
WordPress WordPress 0.7 |
| Not Vulnerable: | |
Discussion
Wordpress Remote PHP File Include Vulnerability
A vulnerability has been reported for Wordpress. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, an attacker may be capable of including a malicious remote PHP file on the target server.
Successful exploitation of this vulnerability would allow an attacker to execute arbitrary PHP commands on a target server, with the privileges of Wordpress.
A vulnerability has been reported for Wordpress. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, an attacker may be capable of including a malicious remote PHP file on the target server.
Successful exploitation of this vulnerability would allow an attacker to execute arbitrary PHP commands on a target server, with the privileges of Wordpress.
Exploit / POC
Wordpress Remote PHP File Include Vulnerability
No exploit required.
No exploit required.
Solution / Fix
Wordpress Remote PHP File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Wordpress Remote PHP File Include Vulnerability
References:
References:
- WordPress 0.7 (FraMe (frame at kernelpanik.org))
- WordPress Homepage (WordPress)