PT-2017-7400 · WordPress · Gwolle Guestbook

Published

2017-09-11

·

Updated

2018-10-09

·

CVE-2015-8351

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gwolle Guestbook plugin versions prior to 1.5.4
Description The issue allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to "frontend/captcha/ajaxresponse.php". This can also be leveraged to include and execute arbitrary local files via directory traversal sequences, regardless of whether allow url include is enabled.
Recommendations For versions prior to 1.5.4, update to version 1.5.4 or later to resolve the issue. As a temporary workaround, consider disabling the allow url include setting to minimize the risk of exploitation. Restrict access to the "frontend/captcha/ajaxresponse.php" endpoint to minimize the risk of exploitation. Avoid using the abspath parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8351

Affected Products

Gwolle Guestbook