Hello list!
I want to inform you about vulnerabilities in LBG Zoom In/Out Effect Slider
plugin for WordPress. In addition to one XSS in this plugin, which was
disclosed earlier
(http://packetstormsecurity.com/files/123367/WordPress-LBG-Zoominoutslider-Cross-Site-Scripting.html).
These are Cross-Site Scripting and Full path disclosure vulnerabilities.
Altogether 26 new holes: 24 XSS and 2 FPD vulnerabilities.
-------------------------
Affected products:
-------------------------
Vulnerable are all versions of plugin LBG Zoom In/Out Effect Slider for
WordPress.
----------
Details:
----------
Cross-Site Scripting (WASC-08):
XSS in files add_playlist_record.php and settings_form.php.
LBG Zoominoutslider XSS.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-2.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-3.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-4.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-5.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-6.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-7.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-8.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-9.html
LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013
MustLive. http://websecurity.com.ua
Full path disclosure (WASC-13):
http://site/wp-content/plugins/lbg_zoominoutslider/tpl/banners.php
http://site/wp-content/plugins/lbg_zoominoutslider/tpl/playlist.php
Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua