WordPress eShop plug-in Arbitrary File Overwrite Vulnerability (CVE-2015-3421)
WordPress eShop plug-in Arbitrary File Overwrite Vulnerability (CVE-2015-3421)
Release date:
Updated on:
Affected Systems:
WordPress eShop <= 6.3.11
Description:
Bugtraq id: 74477
CVE (CAN) ID: CVE-2015-3421
EShop is a shopping cart plug-in for WordPress.
EShop does not effectively verify user input in the "eshopcart" HTTP cookie. There is a security vulnerability in implementation. Remote attackers can exploit this vulnerability to overwrite any php variable in the context of the affected application, arbitrary php code execution.
<* Source: High-Tech Bridge Security Research Lab
Link: https://www.htbridge.com/advisory/HTB23255
*>
Test method:
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
High-Tech Bridge Security Research Lab () provides the following test methods:
GET/shopping-cart-2/check/HTTP/1.1
Cookie: eshopcart = wpdb % 3d1% 7C;
GET/shopping-cart-2/check/HTTP/1.1
Cookie: eshopcart = phone % 3dsdfg '"> <script> alert (/ImmuniWeb/) </script>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/
This article permanently updates the link address: