WordPress WP Marketplace Plugin File Enumeration Weakness and File Upload Vulnerabilities

The WP Marketplace Plugin for WordPress is prone to a file-enumeration weakness and a file-upload vulnerability.

Exploiting these issues may allow attackers to determine whether certain files reside on the affected computer, disclose sensitive information, or upload and execute arbitrary script code in the context of the webserver. Information obtained may lead to further attacks.

Versions prior to WP Marketplace Plugin 1.2.2 are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus