OSVDB ID: 86399

Title: BBPress Plugin for WordPress Multiple Script Malformed Input Path Disclosure

Info

Disclosure

Aug 31, 2012

Discovery

Unknown

Dates

Exploit

Aug 31, 2012

Solution

Unknown

Description

BBPress Plugin for WordPress contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when certain input is not properly sanitized before being used in the wp/wp-content/plugins/bbpress/topic.php and wp/wp-content/plugins/bbpress/forum.php scripts, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality
Solution: Solution Unknown
Exploit: Exploit Public
Disclosure: Third-party Disputed, Uncoordinated Disclosure
OSVDB: Web Related

Solution

OSVDB is not aware of a solution for this vulnerability. It has been reported that this is not a valid vulnerability. If this is the case, no solution is necessary.

Products

John James Jacoby and Matt Millenweg

BBPress Plugin for WordPress

Unspecified

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86399