vendor:
Gwolle Guestbook WordPress Plugin
by:
High-Tech Bridge Security Research Lab
9
CVSS
CRITICAL
PHP File Inclusion
98
CWE
Product Name: Gwolle Guestbook WordPress Plugin
Affected Version From: 1.5.3
Affected Version To: 1.5.3
Patch Exists: YES
Related CWE: CVE-2015-8351
CPE: a:marcel_pol:gwolle_guestbook
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Remote File Inclusion in Gwolle Guestbook WordPress Plugin
High-Tech Bridge Security Research Lab discovered a critical Remote File Inclusion (RFI) in Gwolle Guestbook WordPress plugin, which can be exploited by non-authenticated attacker to include remote PHP file and execute arbitrary code on the vulnerable system. HTTP GET parameter 'abspath' is not being properly sanitized before being used in PHP require() function. A remote attacker can include a file named 'wp-load.php' from arbitrary remote server and execute its content on the vulnerable web server.
Mitigation:
Update to Gwolle Guestbook 1.5.4