WordPress Mac Photo Gallery plugin “albid” arbitrary file disclosure vulnerability

Advisory
Secunia Advisory SA 49650

Analysis
This vulnerability relies on a lack of validation of the “albid” in macdownload.php, which is passed straight into the path that is read at line 37 into the response. This cases an arbitrary file disclosure vulnerability.

If we make a request like this, it will cause the code to read out the wp-config.php file, which will contain database credentials in.

Leave a Reply