Release date:
Updated on:
Affected Systems:
WordPress Google Doc Embedder 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57133
CVE (CAN) ID: CVE-2012-4915
The Google Doc Embedder plug-in can embed MS Office, PDF, and other file systems into webpages.
Google Doc Embedder 2.4.6 and other versions have the Arbitrary File leakage vulnerability, wp-content/plugins/google-document-embedder/libs/pdf. the "file" parameter value of php (when "fn" is set to a valid value) is not correctly verified. Attackers can construct malicious directory traversal sequences to obtain Arbitrary File Content.
<* Source: Charlie Eriksen
Link: http://www.securelist.com/en/advisories/50832
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/extend/plugins/google-document-embedder/