Race Condition Vulnerabilities in WordPress Plug-ins

被引:0
|
作者
Miyachi, Rin [1 ]
Nagashima, Konan [1 ]
Saito, Taiichi [1 ]
机构
[1] Tokyo Denki Univ, Senju Asahicho, Adachiku 1208551, Japan
来源
ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2024 | 2024年 / 14977卷
关键词
Race Condition; TOCTOU; WordPress; Web Security;
D O I
10.1007/978-981-97-7737-2_10
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
WordPress is the world's most popular content management system, developed as an open-source software with many plugins. However, since these plugins are developed and released by anyone, they may have security problems. Web applications need to be designed and developed in consideration of possible race conditions that may occur when multiple processes access shared resources at the same time, but race conditions aren't paid much attention by developers and may result in vulnerability. This vulnerability is known to cause problems such as unauthorized data access, database inconsistency, and file content corruption by an attacker who intentionally creates a race condition. It is also considered that this vulnerability is not as well-known as XSS and SQLi. In this paper, we investigate the race condition vulnerabilities in WordPress plugins. Based on the results of this survey, we discuss the trends and causes of these vulnerabilities, as well as countermeasures for them.
引用
收藏
页码:179 / 194
页数:16
相关论文
共 50 条
  • [21] The visual development of GCC plug-ins with GDE
    Stony Brook University, United States
    Proc. GCC Developers' Summit, (11-29):
  • [22] Navigator Plug-Ins That Liven Up the Web
    P C Magazine: The Independent Guide to IBM - Standard Personal Computers, 1996, 15 (10):
  • [23] PLUG-INS TURN PERSONAL COMPUTERS INTO INSTRUMENTS
    WALLER, L
    ELECTRONICS, 1983, 56 (04): : 46 - 47
  • [24] Photoshop Plug-ins Supporting Visual Design
    Bozkurt, Gulce Bal
    Tari, Sibel
    2018 26TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2018,
  • [25] Duiker intros color symmetry plug-ins
    不详
    COMPUTER GRAPHICS WORLD, 2008, 31 (01) : 6 - 6
  • [27] CHIP AUTOMATICALLY SWITCHES TV PLUG-INS
    ERIKSON, A
    ELECTRONICS-US, 1980, 53 (25): : 78 - +
  • [28] Rich Content Plug-ins for the Teaching Machine
    Norvell, Theodore S.
    Bruce-Lockhart, Michael P.
    ITICSE 2009: PROCEEDING OF THE 2009 ACM SIGSE ANNUAL CONFERENCE ON INNOVATION AND TECHNOLOGY IN COMPUTER SCIENCE EDUCATION, 2009, : 348 - 348
  • [29] Plug-in Programs: Plug-ins add multimedia to your browser
    Rudich, J.
    Link-Up, 13 (06):
  • [30] Ginga-NCL architecture for plug-ins
    Soares, Luiz Fernando G.
    Moreno, Marcio F.
    Marinho, Rafael S.
    SOFTWARE-PRACTICE & EXPERIENCE, 2013, 43 (04): : 449 - 463