Multiple WordPress Themes 'admin-ajax. php' Arbitrary File Download Vulnerability
Release date:
Updated on: 2014-09-03
Affected Systems:
WordPress
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69497
WordPress is a blog platform developed using the PHP language. You can set up your own website on servers that support PHP and MySQL databases.
Multiple WordPress Themes have the Arbitrary File Download Vulnerability in the 'admin-ajax. php' implementation. Attackers can exploit this vulnerability to download arbitrary files from the Web server and obtain sensitive information.
<* Source: Hugo Santiago
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/wp-admin/admin-ajax.php? Action = kbslider_show_image & amp; img = ../wp-config.php
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/
This article permanently updates the link address: