Wordpress Plugins - SlideDeck 2 <== XSS


##################################################
# Description : Wordpress Plugins - SlideDeck 2 <== XSS
# Version : -
# Date : 7/8/2013
# Author : Ryuzaki Lawlet / Fahmi Fisal @Justryuz (ryuzaki_l@y7mail.com)
##################################################

About:
SlideDeck 2 for WordPress is a responsive slider plugin that lets you easily create content
sliders out of almost any content. Connect to a variety of Content Sources like YouTube, Flickr,
WordPress posts and Pinterest to create gorgeous, dynamic sliders in a few clicks - no coding is required.

Vulnerabilities in the SlideDeck 2 plugin for WordPress,
which can be exploited by malicious people to conduct cross-site scripting attacks.
The vulnerabilities are caused due to a bundled vulnerable version of ZeroClipboard.
Cross-Site Scripting vulnerabilities in ZeroClipboard(http://seclists.org/fulldisclosure/2013/Feb/103)
and in multiple web applications.

Affected products:
Vulnerable are all versions

Affected vendors:
SlideDeck 2
http://www.slidedeck.com / http://wordpress.org/plugins/slidedeck2/

Details:
Cross-Site Scripting (WASC-08):
XSS via id parameter and XSS via copying payload into clipboard

POC:
http://site/wp-content/plugins/slidedeck2/js/zeroclipboard/ZeroClipboard.swf?id=\"))}catch(e){}if(!self.a)self.a=!alert(/XSS/)//&width&height

Provided and/or discovered by:
Ryuzaki Lawlet / Fahmi Fisal @justryuz

Postingan terkait:

Belum ada tanggapan untuk "Wordpress Plugins - SlideDeck 2 <== XSS"

Post a Comment