vendor:
WordPress DZS Video Gallery (dzs-videogallery)
by:
aceeeeeeeer
8,8
CVSS
HIGH
Remote and Local File Disclosure
22
CWE
Product Name: WordPress DZS Video Gallery (dzs-videogallery)
Affected Version From: ALL
Affected Version To: ALL
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
WordPress DZS Video Gallery (dzs-videogallery) 3.1.3 Plugins Remote and Local File Disclosure Vulnerability (only .SWF)
A vulnerability in the WordPress DZS Video Gallery (dzs-videogallery) 3.1.3 plugin allows an attacker to remotely and locally disclose files with a .swf extension. This is done by sending a crafted request to the preview.php file, which is located in the deploy/designer/ directory. The request contains a parameter called swfloc, which can be set to a URL pointing to a .swf file or a relative path to a .swf file located on the server.
Mitigation:
Upgrade to the latest version of the WordPress DZS Video Gallery (dzs-videogallery) plugin.