oss-sec mailing list archives

Multiple vulnerabilities affecting three WordPress Plugins (XSS, & PHP object injection)


From: Summer of Pwnage <lists () securify nl>
Date: Sun, 11 Dec 2016 10:02:54 +0100

Please see attached advisories for more information. These issues were found during Summer of Pwnage (https://sumofpwn.nl), a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way.






Attachment: cross_site_request_forgery_in_insert_html_snippet_wordpress_plugin.txt
Description:

Attachment: google_analytics_counter_tracker_wordpress_plugin_unauthenticed_php_object_injection_vulnerability.txt
Description:

Attachment: stored_cross_site_scripting_in_gallery___image_gallery_wordpress_plugin.txt
Description:


Current thread: