WordPress Count Per Day 3.2.3 Cross Site Scripting

2012.08.26
Credit: Crim3R
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

############# # Exploit Title: wordpress Count per Day Cross Site Scripting Vulnerability # # Google Dork:inurl:/wp-content/plugins/count-per-day # # Date: 08/24/2012 # # Author: Crim3R # # Version 3.2.3 # # Vendor Home : http://downloads.wordpress.org/plugin/count-per-day.3.2.3.zip # # Tested on: all # ############# $ $ Author will be not responsible for any damage. $ ################################################################################### ======================================== first notes.php is not restricted to admin and anyone can access it directty by browser => an attacker can add notes witch can be html codes => its Stored Xss goto WP-path/wp-content/plugins/count-per-day/notes.php in the notes section add html code and click Add D3M0 : http://www.christinedesavino.com/blog/wp-content/plugins/count-per-day http://www.dhakadakshinghsc.com/wp-content/plugins/count-per-day/ www.watansport.net/ara/wp-content/plugins/count-per-day/ ===============Crim3R@Att.Net=========== $home = %00 thanks to : 2MzRp - Mikili - 0x0ptim0us - iC0d3R - farbodmahini & Amir

References:

http://downloads.wordpress.org/plugin/count-per-day.3.2.3.zip


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top