Slideshow Plugin for WordPress 'settings.php' Multiple Parameter XSS

medium Nessus Plugin ID 63302

Synopsis

The remote web server hosts a PHP script that is affected by multiple cross-site scripting vulnerabilities.

Description

The version of Slideshow Plugin for WordPress installed on the remote host fails to properly sanitize user-supplied input to the 'settings' and 'inputFields' parameters of the 'settings.php' script before using them to generate dynamic HTML output. An attacker can leverage these issues to inject arbitrary HTML and script code into a user's browser to be executed within the security context of the affected site.
Successful exploitation of these vulnerabilities requires that PHP's 'register_globals' setting is set to 'on'.

Note that the install is also reportedly affected by an additional cross-site scripting issue as well as multiple path disclosure vulnerabilities; however, Nessus has not tested for these issues.

Solution

Upgrade to version 2.1.13 or later.

See Also

http://www.waraxe.us/content-92.html

http://www.nessus.org/u?a09e3308

Plugin Details

Severity: Medium

ID: 63302

File Name: wordpress_slideshow_multiple_xss.nasl

Version: 1.8

Type: remote

Published: 12/19/2012

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:wordpress:wordpress

Required KB Items: installed_sw/WordPress, www/PHP

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 10/17/2011

Reference Information

BID: 56090

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990