Release date:
Updated on: 2013-03-10
Affected Systems:
WordPress WP Online Store Plugin 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57963
The WordPress WP Online Store plug-in can integrate the osCommerce eCommerce shopping cart into any WordPress topic.
WP Online Store 1.3.1 has a security vulnerability, which can be exploited by malicious users to leak sensitive information.
1) The "turl" and "file" parameters in index. php are used to display files without being correctly verified. Arbitrary files may be leaked through the directory traversal sequence.
2) If the "slug" parameter in index. php is not correctly verified, it is used to include files. Any files containing local resources can be obtained through directory traversal.
<* Source: Charlie Eriksen
Link: http://secunia.com/advisories/50836/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/extend/plugins/wp-online-store/