Race Condition Vulnerabilities in WordPress Plug-ins

被引:0
|
作者
Miyachi, Rin [1 ]
Nagashima, Konan [1 ]
Saito, Taiichi [1 ]
机构
[1] Tokyo Denki Univ, Senju Asahicho, Adachiku 1208551, Japan
关键词
Race Condition; TOCTOU; WordPress; Web Security;
D O I
10.1007/978-981-97-7737-2_10
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
WordPress is the world's most popular content management system, developed as an open-source software with many plugins. However, since these plugins are developed and released by anyone, they may have security problems. Web applications need to be designed and developed in consideration of possible race conditions that may occur when multiple processes access shared resources at the same time, but race conditions aren't paid much attention by developers and may result in vulnerability. This vulnerability is known to cause problems such as unauthorized data access, database inconsistency, and file content corruption by an attacker who intentionally creates a race condition. It is also considered that this vulnerability is not as well-known as XSS and SQLi. In this paper, we investigate the race condition vulnerabilities in WordPress plugins. Based on the results of this survey, we discuss the trends and causes of these vulnerabilities, as well as countermeasures for them.
引用
收藏
页码:179 / 194
页数:16
相关论文
共 50 条