Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

Vulnerabilities in plugins for WordPress

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


mustlive at websecurity

Nov 21, 2009, 1:25 PM

Post #1 of 1 (250 views)
Permalink
Vulnerabilities in plugins for WordPress

Hello Full-Disclosure!

I want to tell you about different vulnerabilities in plugins for WordPress.
About some of them there were posts to Bugtraq list earlier.

This August I made a summary about all vulnerabilities in plugins for
WordPress (http://websecurity.com.ua/3397/), which I found during 2006-2009.

In this list 135 different vulnerabilities are mentioned in 20 plugins for
WordPress. Including Cross-Site Scripting, Insufficient Anti-automation,
Cross-Site Request Forgery, Directory Traversal, Arbitrary File Deletion,
Denial of Service, Full path disclosure, Insufficient Authorization,
Information Leakage, Abuse of Functionality, HTTP Response Splitting, SQL
Injection and CRLF Injection vulnerabilities.

Most posts mentioned in the list are on Ukrainian (so use Google Translate),
but some of them are on English - posts from my Month of Bugs in Captchas
(MoBiC) project, which I made in 2007. Take care of your plugins for WP and
web sites which use them.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.