Vulnerable Systems:
* Floating Tweets Plugin for WordPress 1.0.1
Floating Tweets Plugin for WordPress contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the skin.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow a remote attacker to gain access to arbitrary files.
Disclosure Timeline:
Vendor Informed Date :2012-08-31
Disclosure Date :2012-12-11
Exploit Publish Date :2013-01-11