Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [Full-disclosure] IntraProgrammed Search Engines Are XSS Driven

  [ECHO_ADV_77$2007] Study planner (Studiewijzer)
<= 0.15 Remote File Inclusion Vulnerability

  **SubHub v2.3.0**

  Web Wiz Forums 8.05 (MySQL version) SQL Injection

From:Metaeye SG <contact_(at)_metaeye.org>
Date:22.03.2007
Subject:Advisory - Redirection Vulnerability in wp-login.php.

Vendor
------
Wordpress (http://www.wordpress.org).

Severity
--------
Moderate.

Dated
-----
03 March 2007.

Versions Affected
-----------------
All.

Issue
-----

The wp-login.php page redirects a user to arbitrary page after
successful login by setting the redirect_to url parameter.

For example if a user logins successfully with his credentials
on the following page

http://www.foo.com/wp-login.php?redirect_to=http://www.google.co.in

He will be redirected to www.google.co.in.

Impact
------

This can lead to credentials stealing. Also cookie stealing
is possible coupled with some browser bugs.

Vendor Status
-------------
Reported on 03 March 2007. Fix will be made available in next version.

--
MSG // http://www.metaeye.org

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru