CVE-2012-6651 Information

Description

Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

Reference

http://wordpress.org/plugins/vitamin/changelog/ http://www.openwall.com/lists/oss-security/2014/07/24/6 http://www.openwall.com/lists/oss-security/2014/07/28/3 http://www.securityfocus.com/bid/54856 https://plugins.trac.wordpress.org/changeset/582232

Share on: