WordPress Plugin Vulnerabilities

Google Adsense & Hotel Booking <= 1.0.5 - Open Proxy

Description

Plugin is still affected and has been closed.

The code in ./plugin/google-adsense-and-hotel-booking/proxy.php allows an arbitrary user to proxy POST requests though the host site.

This may allow attackers to hide attacks, or DoS a site if the POST request is pointed back at itself causing a loop.

Proof of Concept

Affects Plugins

References

Classification

Type
REDIRECT
OWASP top 10
CWE

Miscellaneous

Submitter
Larry W. Cashdollar
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-08-15 (about 10 years ago)
Added
2015-08-24 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other