Release date:
Updated on: 2013-01-12
Affected Systems:
WordPress Gallery 3.8.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57256
WordPress Gallery is a variety of library plug-ins used on WordPress.
WordPress Gallery plug-in 3.8.3 and other versions do not properly validate the filename_1 parameter value in the gallery-plugin.php, resulting in remote attackers can construct parameters to access arbitrary files, resulting in arbitrary file leakage vulnerability.
<* Source: Beni_Vanda
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/wp-content/plugins/gallery-plugin/gallery-plugin.php? Filename_1 = [AFR]
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/