VULNERABILITIES / FIXES - April 17, 2012
by Carol~
- 4/17/12 5:09 AM
WordPress Yahoo Answer WordPress Auto Poster Plugin Two Cross-Site Scripting Vulnerabilities
Release Date : 2012-04-17
Criticality level : Less critical
Impact : Cross Site Scripting
Where : From remote
Solution Status : Unpatched
Software: WordPress Yahoo Answer WordPress Auto Poster Plugin
Description:
Ryuzaki Lawlet has reported two vulnerabilities in the Yahoo Answer WordPress Auto Poster plugin for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.
Input passed via the "catname" parameter to process-imported-question.php and the "query" parameter to editautopilot.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
Ryuzaki Lawlet.
Original Advisory:
http://justryuz.blogspot.com/view/sidebar#!/2012/04/wo0t-yahoo-answer-wordpress-auto.html
http://secunia.com/advisories/48862/

Moderator
CNET Staff
Samsung Staff
Dell Staff