Wordpress Securimage-WP Plugin v3.2.4 URI-based XSS Vulnerability


Vendor: Securimage PHP CAPTCHA
Product web page: https://wordpress.org/extend/plugins/securimage-wp/
Affected version: 3.2.4

Summary: Securimage-WP adds powerful CAPTCHA protection to
comment forms on posts and pages to help prevent comment
spam from getting onto your site.

Desc: Securimage-WP suffers from a XSS issue in 'siwp_test.php'
that uses the 'PHP_SELF' variable. The vulnerability is
present because there isn't any filtering to the mentioned
variable in the affected script. Attackers can exploit this
weakness to execute arbitrary HTML and script code in a user's
browser session.

Tested on: Microsoft Windows 7 Ultimate SP1 (EN)
           Apache 2.4.2 (Win32)
           PHP 5.4.7
           MySQL 5.5.25a


Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
                            @zeroscience


Advisory ID: ZSL-2013-5140
Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5140.php


24.04.2013

--


http://localhost/wordpress/wp-content/plugins/securimage-wp/siwp_test.php/"/><script>alert(document.cookie);</script>?tested=1