WordPress.org

Ready to get started?Download WordPress

Forums

Grand Flagallery - Photo Gallery Plugin
[resolved] [Plugin: GRAND FlAGallery] Security Vulnerability (2 posts)

  1. Beshoy Girgis
    Member
    Posted 1 year ago #

    I have reason to believe this plugin has a security vulnerability. I have an IP targeting files in this extension with hundreds of the following in my access log:

    75.81.24.2 - - [04/Oct/2012:01:00:04 +0000] "POST /wp-content/plugins/flash-album-gallery/lib/hitcounter.php HTTP/1.1" 403 220

    I added a "deny from 75.81.24.2" in my htaccess which resulted in:

    [Thu Oct 04 01:00:04 2012] [error] [client 75.81.24.2] client denied by server configuration: PATH/wp-content/plugins/flash-album-gallery/lib/hitcounter.php, referer: http://DOMAIN/wp-content/plugins/flagallery-skins/stylishgrey/gallery.swf

    I'm not sure what the vulnerability the hacker's script is trying to take advantage of but I thought you should know.

    http://wordpress.org/extend/plugins/flash-album-gallery/

  2. Rattus
    Member
    Plugin Author

    Posted 1 year ago #

    hitcounter.php is a script for view and rating statistic of each image.
    Every time someone view the picture in the gallery, SWF post 'view+1' to hitcounter.php and this script write this information to database.

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic

Tags

No tags yet.