Hello list! I want to inform you about vulnerabilities in LBG Zoom In/Out Effect Slider plugin for WordPress. In addition to one XSS in this plugin, which was disclosed earlier (http://packetstormsecurity.com/files/123367/WordPress-LBG-Zoominoutslider-Cross-Site-Scripting.html). These are Cross-Site Scripting and Full path disclosure vulnerabilities. Altogether 26 new holes: 24 XSS and 2 FPD vulnerabilities. ------------------------- Affected products: ------------------------- Vulnerable are all versions of plugin LBG Zoom In/Out Effect Slider for WordPress. ---------- Details: ---------- Cross-Site Scripting (WASC-08): XSS in files add_playlist_record.php and settings_form.php. LBG Zoominoutslider XSS.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-2.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-3.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-4.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-5.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-6.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-7.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-8.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
LBG Zoominoutslider XSS-9.html LBG Zoom In/Out Effect Slider for WordPress XSS exploit (C) 2013 MustLive. http://websecurity.com.ua
Full path disclosure (WASC-13): http://site/wp-content/plugins/lbg_zoominoutslider/tpl/banners.php http://site/wp-content/plugins/lbg_zoominoutslider/tpl/playlist.php Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua