Skip to main content

Wordpress DukaPress Plugin Sensitive Information Disclosure Vulnerability

Last Update Date: 28 Nov 2014 09:27 Release Date: 28 Nov 2014 3621 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability was identified in the DukaPress Plugin for Wordpress, which can be exploited by malicious people to disclose sensitive information.

Input passed via the "src" GET parameter to \lib\dp_image.php is not properly verified before being used to read files. This can be exploited to disclose the contents of arbitrary local files via directory traversal sequences.


Impact

  • Information Disclosure

System / Technologies affected

  •  Versions prior to 2.5.4

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 2.5.4

Vulnerability Identifier


Source


Related Link