Release date:
Updated on: 2013-02-02
Affected Systems:
WordPress Gallery 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57650
CVE (CAN) ID: CVE-2012-4919
WordPress Gallery is a variety of library plug-ins used on WordPress.
Gallery 1.4 and earlier versions do not correctly verify the "load" parameter value of wp-content/plugins/wordpress-gallery/functions/update_order.php, which is used to include files, attackers can exploit arbitrary files that contain remote resources.
<* Source: Charlie Eriksen
Link: http://secunia.com/advisories/51347/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/