Release date:
Updated on: 2012-11-01
Affected Systems:
WordPress Slideshow Plugin 2.x
Description:
--------------------------------------------------------------------------------
WordPress is a Blog (Blog, Blog) engine developed using the PHP language and MySQL database. you can create your own Blog on servers that support PHP and MySQL databases.
Multiple vulnerabilities exist in WordPress Slideshow plug-in 2.1.14 and other versions, which can be exploited by malicious users to execute script insertion attacks.
1) Pass the "videoId", "url", "title", and "description" values of the "slides" array to views/SlideshowPlugin/slideshow. php input is used if it is not properly filtered. Attackers can insert and execute arbitrary HTML and script code.
2) input is passed to classes/SlideshowPluginPostType through the "slideSpeed", "descriptionSpeed", "intervalSpeed", "slidesPerView", "width", "height", and "descriptionHeight" values of the "data" array.. php input is used if it is not properly filtered. Attackers can insert and execute arbitrary HTML and script code.
<* Source: SVN
Link: http://secunia.com/advisories/51135/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://plugins.trac.wordpress.org/browser/slideshow-jquery-image-gallery/trunk