OSVDB ID: 83722

Title: Global Content Blocks Plugin for WordPress Multiple Script Code Block Information Disclosure

Info

Disclosure

Jul 12, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Jul 12, 2012

Description

Global Content Blocks Plugin for WordPress contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the wp-content/plugins/global-content-blocks/resources/tinymce/gcbvalue.php and wp-content/plugins/global-content-blocks/gcb/gcb_export.php scripts fail to properly restrict access. This may allow a remote attacker to gain acccess to arbitrary code block information.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Solution: Upgrade
Exploit: Exploit Private
Disclosure: Third-party Verified, Coordinated Disclosure
OSVDB: Web Related

Solution

Upgrade to version 1.5.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

WP Xpert

Global Content Blocks Plugin for WordPress

1.5.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/83722