Race Condition Vulnerabilities in WordPress Plug-ins

被引:0
|
作者
Miyachi, Rin [1 ]
Nagashima, Konan [1 ]
Saito, Taiichi [1 ]
机构
[1] Tokyo Denki Univ, Senju Asahicho, Adachiku 1208551, Japan
来源
ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2024 | 2024年 / 14977卷
关键词
Race Condition; TOCTOU; WordPress; Web Security;
D O I
10.1007/978-981-97-7737-2_10
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
WordPress is the world's most popular content management system, developed as an open-source software with many plugins. However, since these plugins are developed and released by anyone, they may have security problems. Web applications need to be designed and developed in consideration of possible race conditions that may occur when multiple processes access shared resources at the same time, but race conditions aren't paid much attention by developers and may result in vulnerability. This vulnerability is known to cause problems such as unauthorized data access, database inconsistency, and file content corruption by an attacker who intentionally creates a race condition. It is also considered that this vulnerability is not as well-known as XSS and SQLi. In this paper, we investigate the race condition vulnerabilities in WordPress plugins. Based on the results of this survey, we discuss the trends and causes of these vulnerabilities, as well as countermeasures for them.
引用
收藏
页码:179 / 194
页数:16
相关论文
共 50 条
  • [41] Plug-ins for critical media literacy: A collaborative program
    Robinson, Ashley
    Nelson, Elizabeth
    2002, Online Inc. (26):
  • [42] Plug-ins - 3D animation is a craft
    不详
    COMPUTER GRAPHICS WORLD, 2006, 29 (10) : 4 - 4
  • [43] PLUG-INS ELECTRIFY 3D STUDIO
    ROBERTSON, B
    COMPUTER GRAPHICS WORLD, 1995, 18 (05) : 36 - +
  • [45] Survival of Eclipse Third-party Plug-ins
    Businge, John
    Serebrenik, Alexander
    van den Brand, Mark
    2012 28TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE (ICSM), 2012, : 368 - 377
  • [46] Extending eclipse RCP with dynamic update of active plug-ins
    Gregersen, Allan Raundahl
    Jorgensen, Bo Norregaard
    JOURNAL OF OBJECT TECHNOLOGY, 2007, 6 (06): : 67 - 89
  • [47] PCI becomes the mainstream for data-acq plug-ins
    Pers Eng Instrum News, 6 (55):
  • [48] First Workshop on Developing Tools as Plug-ins (TOPI 2011)
    Bishop, Judith
    Notkin, David
    Breitman, Karin
    2011 33RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2011, : 1230 - 1231
  • [49] The Development of an Extensible CAD/CAM Framework based on Plug-ins
    Huang Changbiao
    Jiang Kaiyong
    Lin Junyi
    Liu Bin
    2009 INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION, VOL III, 2009, : 142 - 145
  • [50] VERSATILE ANALOG CHIP FOR OSCILLOSCOPE PLUG-INS .2.
    ADDIS, J
    ELECTRONIC ENGINEERING, 1988, 60 (741): : 37 - &