Wordpress DukaPress Plugin Sensitive Information Disclosure Vulnerability
Last Update Date:
28 Nov 2014 09:27
Release Date:
28 Nov 2014
3621
Views
RISK: Medium Risk
TYPE: Servers - Web Servers
A vulnerability was identified in the DukaPress Plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information.
Input passed via the "src" GET parameter to \lib\dp_image.php is not properly verified before being used to read files. This can be exploited to disclose the contents of arbitrary local files via directory traversal sequences.
Impact
- Information Disclosure
System / Technologies affected
- Versions prior to 2.5.4
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 2.5.4
Vulnerability Identifier
Source
Related Link
Share with