WordPress GRAND Flash Album Gallery Plugin Multiple Remote Vulnerabilities
19 Dec. 2012
Summary
GRAND Flash Album Gallery for WordPress is prone to following multiple vulnerabilities: 1. Multiple SQL-injection vulnerabilities
2. Multiple directory-traversal vulnerabilities 3. Multiple arbitrary file-overwrite vulnerabilities.
Credit:
The information has been provided by Janek Vind /B>.
Vulnerable Systems:
* WordPress GRAND Flash Album Gallery plugin 1.90 and prior
GRAND Flash Album Gallery plugin for WordPress could allow a remote attacker to traverse directories on the system. A remote authenticated attacker could send a specially-crafted URL request to the ajax.php, facebook.php and news.php scripts containing dot dot sequences (/../) in the dir, 'f' and want2Read parameters to view arbitrary files on the system.