- 전체
- 보안뉴스
- 제로데이취약점
- 해킹프로그래밍
- 웹해킹
- 해킹기법
- 정보보호
- 정보보안기사 - 국가기술자격
- 악성코드분석_리버싱
- 시큐어코딩_개발보안진단원
- CISSP
- CISA
- 모의해킹_penetration-test
- deepweb / tor network
- Kali Linux
제로데이취약점 Wordpress Buddypress Plugin 1.9.1 - Privilege Escalation
2014.02.17 13:08
Wordpress Buddypress Plugin 1.9.1 - Privilege Escalation
# Exploit Title: Wordpress plugin Buddypress <= 1.9.1 privilege escalation# Date: 11/02/2014# Exploit Author: Pietro Oliva# Vendor Homepage: http://buddypress.org# Software Link: http://downloads.wordpress.org/plugin/buddypress.1.9.1.zip# Version: 1.9.1# CVE : [CVE-2014-1889]# Vulnerability patched in version 1.9.2it is possible to perform a privilege escalation attack due to a lack ofpermissions check in the group creation process. A malicious user couldexploit this vulnerability to take control of every group (change name,description, avatar and settings).To exploit this vulnerability you have to follow these steps:1) Create a cookie named bp_new_group_id=<id_of_victim_group>2) Visit the url http://example.com/groups/create/step/group-details/3) Enjoy the power |
본 웹사이트는 광고를 포함하고 있습니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
댓글 0
| 번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
|---|---|---|---|---|
| 공지 | 침투테스트(취약점검점검, 모의해킹) 문의 / 답변 | 졸리운_곰 | 2017.12.10 | 28360 |
| 4 |
시큐어코딩 수행 [템플릿]
| 졸리운_곰 | 2017.11.18 | 281 |
| 3 |
효과적인 시큐어 코딩 적용을 위한 팁
| 졸리운_곰 | 2017.05.07 | 190 |
| 2 |
소프트웨어 개발보안(시큐어 코딩) 관련 가이드
| 졸리운_곰 | 2014.10.26 | 378 |
| 1 |
소프트웨어 보안약점 진단가이드 [안전행정부/한국인터넷진흥원]
| 졸리운_곰 | 2014.10.26 | 417 |

