YouTube Embed Plugin up to 3.3.2 on WordPress options-profiles.php youtube_embed_name cross site scripting : 9/1/2015 5:09:03 AM
Communicate with co-workers in real time. Used by Netflix, Dropbox & Salesforce. $0/unlimited users. Get started >> From our sponsors |
Vulnerability Advisories |
Vulnerabilities of scip VulDB |
YouTube Embed Plugin up to 3.3.2 on WordPress options-profiles.php youtube_embed_name cross site scripting
8/30/2015 7:00:00 PM
General
scipID: 77503
Affected: YouTube Embed Plugin up to 3.3.2
Published: 08/31/2015
Risk: problematic
Created: 09/01/2015
Entry: 66.8% complete
Summary
A vulnerability has been found in YouTube Embed Plugin up to 3.3.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown function of the file includes/options-profiles.php. The manipulation of the argument youtube_embed_name
with an unknown input leads to a cross site scripting vulnerability. As an impact it is known to affect integrity. The summary by CVE is:
Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).
The weakness was presented 08/31/2015. This vulnerability is known as CVE-2015-6535. The exploitation appears to be easy. The attack can be launched remotely. Technical details of the vulnerability are known, but there is no available exploit.
By approaching the search of inurl:includes/options-profiles.php it is possible to find vulnerable targets with Google Hacking.
Upgrading to version 3.3.3 eliminates this vulnerability.CVSS
Base Score: 4.0 (CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N) [?]
Temp Score: 3.5 (CVSS2#E:ND/RL:OF/RC:ND) [?]
CPE
- cpe:/a:youtube_embed_plugin:youtube_embed_plugin:3.3.0
- cpe:/a:youtube_embed_plugin:youtube_embed_plugin:3.3.1
- cpe:/a:youtube_embed_plugin:youtube_embed_plugin:3.3.2
Exploiting
Class: Cross site scripting
Local: No
Remote: Yes
Availability: No
Google Hack: inurl:includes/options-profiles.php
Countermeasures
Recommended: Upgrade
Status: Official fix
0-Day Time: 0 days since found
Upgrade: YouTube Embed Plugin 3.3.3
Timeline
08/31/2015 | Advisory disclosed
09/01/2015 | VulDB entry created
09/01/2015 | VulDB entry updated
Sources
CVE: CVE-2015-6535 (mitre.org) (nvd.nist.org) (cvedetails.com)
You are receiving this email because you subscribed to this feed at feedmyinbox.com
If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions