PT-2008-2137 · Dean · Dean'S Permalinks Migration
G30Rg3_X
·
Publicado
2008-01-31
·
Atualizado
2018-10-15
·
CVE-2008-0508
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dean's Permalinks Migration plugin version 1.0
Description
A cross-site request forgery (CSRF) issue allows remote attackers to modify the
oldstructure configuration setting, also known as dean pm config[oldstructure], as administrators. This is achieved via the old struct parameter in a deans permalinks migration.php action to wp-admin/options-general.php. An example of exploitation includes placing an XSS sequence in this setting.Recommendations
For Dean's Permalinks Migration plugin version 1.0, consider disabling access to the
deans permalinks migration.php file until a patch is available to prevent modification of the oldstructure setting. Restrict access to the wp-admin/options-general.php page to minimize the risk of exploitation. Avoid using the old struct parameter in the affected action until the issue is resolved.Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dean'S Permalinks Migration