WordPress Simple Gmail Login Path Disclosure

2012.12.09
Risk: Low
Local: No
Remote: Yes
CWE: CWE-200


CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: None
Availability impact: None

################ Application- Wordpress Plugin Simple Gmail Login Exploit - Stack Trace Error URL- http://wordpress.org/extend/plugins/simple-gmail-login/ ################ Author- Aditya Balapure Link - http://adityabalapure.blogspot.in/ CVE Assigned- CVE-2012-6313. ################ Description Once you have installed this plugin you can login to wp-admin using your ordinary user name (or your email) and your password on GMail (your old wordpress password still works as well). Another feature of this plugin is that you will get a log of everybody that logs into your wordpress application. In case you're having problems with this plugin you will find information about that in the same log. ################ Fatal error: Uncaught exception 'Exception' with message 'DateTimeZone::__construct() [<a href='datetimezone.--construct'>datetimezone.--construct</a>]: Unknown or bad timezone ()' in C:\xampp\htdocs\wordpress\wp-content\plugins\simple-gmail-login\simple-gmail-login.php:229 Stack trace: #0 C:\xampp\htdocs\wordpress\wp-content\plugins\simple-gmail-login\simple-gmail-login.php(229): DateTimeZone->__construct('') #1 C:\xampp\htdocs\wordpress\wp-content\plugins\simple-gmail-login\simple-gmail-login.php(210): SimpleGmail_Plugin->log('Plugin activate...', false) #2 [internal function]: SimpleGmail_Plugin->activate('') #3 C:\xampp\htdocs\wordpress\wp-includes\plugin.php(403): call_user_func_array(Array, Array) #4 C:\xampp\htdocs\wordpress\wp-admin\plugins.php(157): do_action('activate_simple...') #5 {main} thrown in C:\xampp\htdocs\wordpress\wp-content\plugins\simple-gmail-login\simple-gmail-login.php on line 229 ################ Vendor- Informed, Patched & closed URL - http://wordpress.org/extend/plugins/simple-gmail-login/changelog/

References:

http://wordpress.org/extend/plugins/simple-gmail-login/
http://wordpress.org/extend/plugins/simple-gmail-login/changelog/
http://adityabalapure.blogspot.in/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top