CVE-2016-0796
mb.miniAudioPlayer – an HTML5 audio player for your mp3 files に報告された脆弱性
概要
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind vulnerable website or to perform otherwise restricted actions and subsequently download files with the extension mp3, mp4a, wav and ogg from anywhere the web server application has read access to the system. WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files version 1.7.6 is vulnerable; prior versions may also be affected.
影響を受けるバージョン
- 1.7.6 以下
対処方法
修正版が公表されていません。最新版への更新、無効化、または代替プラグインへの移行を検討してください。
この脆弱性は実証コードが公開されています。攻撃に利用されやすい状態のため、優先して対応してください。
mb.miniAudioPlayer – an HTML5 audio player for your mp3 files の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- http://www.vapidlabs.com/advisory.php?v=162
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-mb-miniaudioplayer-an-html5-audio-player-for-your-mp3-files-multiple-vulnerabilities-1-7-6/
- http://www.vapidlabs.com/advisory.php?v=162
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-mb-miniaudioplayer-an-html5-audio-player-for-your-mp3-files-multiple-vulnerabilities-1-7-6/