Release date: 2012-3 3
Updated on:
Affected Systems:
WordPress WP-Realty
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56780
WordPress WP-Realty is a real estate plug-in.
WordPress's WP-Realty plugin has a local file inclusion vulnerability. Attackers can exploit this vulnerability to view files and execute local scripts in Web server processes.
<* Source: Amirh03in
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
An attacker can exploit the issue through a browser.
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Disable WordPress WP-Realty.
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/