Quantcast
Channel: Files from Christian Mehlmauer ≈ Packet Storm
Viewing all articles
Browse latest Browse all 18

Wordpress WPTouch Authenticated File Upload

$
0
0
The Wordpress WPTouch plugin contains an authenticated file upload vulnerability. A wp-nonce (CSRF token) is created on the backend index page and the same token is used on handling ajax file uploads through the plugin. By sending the captured nonce with the upload, we can upload arbitrary files to the upload folder. Because the plugin also uses it's own file upload mechanism instead of the wordpress api it's possible to upload any file type. The user provided does not need special rights. Also users with "Contributer" role can be abused.

Viewing all articles
Browse latest Browse all 18

Latest Images

Trending Articles



Latest Images