YouTube Embed Plugin up to 3.3.2 on WordPress options-profiles.php youtube_embed_name cross site scripting : 9/1/2015 5:09:03 AM

Communicate with co-workers in real time. Used by Netflix, Dropbox & Salesforce. $0/unlimited users. Get started >>
From our sponsors
 

 

Vulnerability Advisories
Vulnerabilities of scip VulDB

YouTube Embed Plugin up to 3.3.2 on WordPress options-profiles.php youtube_embed_name cross site scripting
8/30/2015 7:00:00 PM

General

scipID: 77503
Affected: YouTube Embed Plugin up to 3.3.2
Published: 08/31/2015
Risk: problematic

Created: 09/01/2015
Entry: 66.8% complete

Summary

A vulnerability has been found in YouTube Embed Plugin up to 3.3.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown function of the file includes/options-profiles.php. The manipulation of the argument youtube_embed_name with an unknown input leads to a cross site scripting vulnerability. As an impact it is known to affect integrity. The summary by CVE is:

Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).

The weakness was presented 08/31/2015. This vulnerability is known as CVE-2015-6535. The exploitation appears to be easy. The attack can be launched remotely. Technical details of the vulnerability are known, but there is no available exploit.

By approaching the search of inurl:includes/options-profiles.php it is possible to find vulnerable targets with Google Hacking.

Upgrading to version 3.3.3 eliminates this vulnerability.

CVSS

Base Score: 4.0 (CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N) [?]
Temp Score: 3.5 (CVSS2#E:ND/RL:OF/RC:ND) [?]

CPE

Exploiting

Class: Cross site scripting
Local: No
Remote: Yes

Availability: No
Google Hack: inurl:includes/options-profiles.php

Countermeasures

Recommended: Upgrade
Status: Official fix
0-Day Time: 0 days since found

Upgrade: YouTube Embed Plugin 3.3.3

Timeline

08/31/2015 | Advisory disclosed
09/01/2015 | VulDB entry created
09/01/2015 | VulDB entry updated

Sources

CVE: CVE-2015-6535 (mitre.org) (nvd.nist.org) (cvedetails.com)

 

You are receiving this email because you subscribed to this feed at feedmyinbox.com

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

Diberdayakan oleh Blogger.