Release date:
Updated on:
Affected Systems:
WordPress UnGallery Plugin 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56182
WordPress UnGallery is a plug-in that displays the WordPress Image Library directory.
UnGallery 2.1.5 and other versions have the remote command execution vulnerability. php input is not in wp-content/plugins/ungallery/search. correct filtering in php is used in the "find" parameter. Attackers can exploit this vulnerability to execute arbitrary commands in affected applications.
<* Source: Charlie Eriksen
Link: http://secunia.com/advisories/50875/
Http://wordpress.org/extend/plugins/ungallery/changelog/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
WordPress has released a Security Bulletin (2.1.7) and corresponding patches for this purpose:
2.1.7: changelog
Link: http://wordpress.org/extend/plugins/ungallery/changelog/