lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20190317141651.pbue6zqvtwmpcp67@tunkki.bugs.fi>
Date: Sun, 17 Mar 2019 16:16:51 +0200
From: Henri Salo <henri@...v.fi>
To: Manuel Garcia Cardenas <advidsec@...il.com>
Cc: fulldisclosure@...lists.org
Subject: Re: [FD] WordPress Plugin GraceMedia Media Player 1.0 - Local File
 Inclusion

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, Mar 13, 2019 at 08:21:07AM +0100, Manuel Garcia Cardenas wrote:
> - CVE-ID: CVE-2019-9618
> WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion
> /wordpress/wp-content/plugins/gracemedia-media-player/templates/files/ajax_controller.php?ajaxAction=getIds&cfg=../../../../../../../../../../etc/passwd
> 
> VII. SOLUTION
> -------------------------
> Disable plugin until a fix is available, vendor does not fix after 2
> requests.

Good research work Manuel. Keep up the good work! =)

In case of WordPress plugins your solution is not correct. This vulnerability
can be exploited even plugin is disabled. Plugin must be deleted in order to
mitigate this.

- -- 
Henri Salo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE/aVSDznAZReWTkxKJ633pE6qdXQFAlyOVtMACgkQJ633pE6q
dXTdBA/+J/ml4soyBkleh2QO/pCV4NiNeGfyBUU/FkEFAEthPOg4J0w4J526sMzV
hL9Y2GvTK4YnXLxLeksmehKTl8m6rFEDCE7CCTm64xUzZh6zgDHdDjcizyQ27Nes
WLHky0lWBcNT3Agfg+3H7vhPIQGGE3mLmQvxvV5LLpriiAw/rd4eONG5TO9qvzdN
1DQ79F54EPavrv7RARGu4JuXFBprNFm7WpQW1kb+nhsDzv9W5Vd9YcA9I2k+SM6y
WCIQPcyRxs/2kTRxTzV9AZT7R9ggPegeqT30Ir9OlZalUVzXVeeKdE5keflu+SVh
5YnaOBMk7WvAtk/uq9X9/StpxJKqCyIzRYtyp7Ouivqwmj25PIjeLUb1S+wsFQWn
ruEIrFl7ioAEWALfo9FOTVZpjbSAYNB3TINLuQqVf6tjJ+p8j/MJ3F7D2kLDARTM
QUsoJoXLsqJ5Q1OUS9UUqq9BeOcI3TwboKCpweeYRW8CGt+wCMvv8Nr6+XSirV9c
5Icnf7p1kPLwsUQSsC8jsyzfYczBZTfWiTmeKk/+60a2larptPcnrnrYJcj6g2Ae
XD9nv4icaji14/MtaRNUFr1es0B6bKWDKZqGAMTuzrk/A+YWUgZxeV3x0xivOz5G
Ry4dpnjhGHfYqo2fD1RK2/RlmPaBEy03tYCDcyTfaGpyzRTmXWg=
=ZzHz
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists