Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WordPress Sniplets Plugin Multiple Input Validation Vulnerabilities

WordPress Sniplets plugin is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input. These issues include multiple cross-site scripting vulnerabilities, a remote file-include vulnerability, and a remote command-execution vulnerability.

A successful exploit may allow an attacker to compromise the application, steal cookie-based authentication credentials, and execute arbitrary code and commands within the context of the webserver process.


WordPress Sniplets 1.1.2 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus