vendor:
WordPress Plugin
by:
SecurityFocus
4,3
CVSS
MEDIUM
Path Disclosure
200
CWE
Product Name: WordPress Plugin
Affected Version From: 1.9.10
Affected Version To: 1.9.11
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Path Disclosure Vulnerability in NextGEN Gallery Plugin for WordPress
The NextGEN Gallery plugin for WordPress is prone to a path-disclosure vulnerability. An attacker can exploit this issue to obtain sensitive information that may lead to further attacks. The vulnerability is triggered when an attacker sends a specially crafted request to the vulnerable application. This can be done by sending a request to the vulnerable application with the following parameters: http://www.example.com/?callback=json&api_key=true&format=json&method=gallery&id=1 and http://www.example.com/?callback=json&api_key=true&format=xml&method=recent&limit=1
Mitigation:
Upgrade to the latest version of NextGEN Gallery plugin for WordPress