Archive

Archive for May, 2013

WordPress Frontier Post Plugin Publishing Posts Security Bypass

May 27th, 2013
Comments Off

Application: WordPress
Affected Version: version 1.3.3 and other versions.
Vendor’s URL: Frontier Post Plugin
Bug Type: Security Bypass
Risk Level: Critical

Solution:
The vendor has released a fix. However, the fix is not effective. No official solution is currently available.

Access Bypass, Content Management

WordPress Spider Catalog Plugin Cross-Site Scripting and SQL Injection

May 27th, 2013
Comments Off

Application: WordPress
Affected Version: version 1.4.7 and other versions.
Vendor’s URL: Spider Catalog Plugin
Bug Type: Cross-Site Scripting and SQL Injection
Risk Level: Critical

Solution:
No official solution is currently available.

Content Management, Cross Site Scripting, SQL Injection

WordPress SS Quiz Plugin Multiple Unspecified Vulnerabilities

May 27th, 2013
Comments Off

Application: WordPress
Affected Version: versions prior to 2.0.
Vendor’s URL: SS Quiz Plugin
Bug Type: -
Risk Level: Critical

Solution:
Upgrade to version 2.0.

Content Management

WordPress Video Gallery Plugin “playid” SQL Injection

May 27th, 2013
Comments Off

Application: WordPress
Affected Version: versions 1.6 and 2.0 and other versions.
Vendor’s URL: Video Gallery Plugin
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Upgrade or update to version 2.1.

Content Management, SQL Injection

WordPress WP Print Friendly Plugin Security Bypass

May 27th, 2013
Comments Off

Application: WordPress
Affected Version: versions prior to 0.5.3.
Vendor’s URL: WP Print Friendly Plugin
Bug Type: Security Bypass
Risk Level: Critical

Solution:
Update to version 0.5.3.

Access Bypass, Content Management

Joomla! DJ-Classifieds Component “se_regs[]” SQL Injection

May 27th, 2013
Comments Off

Application: Joomla!
Affected Version: version 2.3.2 and other versions.
Vendor’s URL: DJ-Classifieds Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
No official solution is currently available.

Content Management, SQL Injection

YaBB “guestlanguage” Cookie Local File Inclusion

May 27th, 2013
Comments Off

Application: YaBB
Affected Version: version 2.5.2.
Vendor’s URL: YaBB
Bug Type: File Inclusion
Risk Level: Critical

Solution:
Fixed in the SVN repository.

Discussion Boards, File Inclusion

WordPress open-flash-chart-core Plugin Open Flash Chart Arbitrary File Creation

May 27th, 2013
Comments Off

Application: WordPress
Affected Version: versions prior to 0.5.
Vendor’s URL: open-flash-chart-core Plugin
Bug Type: Access Bypass
Risk Level: Critical

Solution:
Update to version 0.5.

Access Bypass, Content Management