Wordpress Theme - Adsense-id <== XSS


##################################################
# Description : Wordpress Theme - Adsense-id <== XSS
# Version : 2
# Date : 7/8/2013
# Author : Ryuzaki Lawlet / Fahmi Fisal @Justryuz (ryuzaki_l@y7mail.com)
##################################################

Vulnerabilities in the Adsense-id theme for WordPress,
which can be exploited by malicious people to conduct cross-site scripting attacks.
The vulnerabilities are caused due to a bundled vulnerable version of ZeroClipboard.
Cross-Site Scripting vulnerabilities in ZeroClipboard(http://seclists.org/fulldisclosure/2013/Feb/103)
and in multiple web applications.

Affected products:
Vulnerable are all versions

Affected vendors / author:
adsense-id virtarich - http://www.fastestwp.com/

Details:
Cross-Site Scripting (WASC-08):
XSS via id parameter and XSS via copying payload into clipboard

POC:
http://site/wp-content/themes/adsense-id/js/ZeroClipboard.swf?id=\"))}catch(e){}if(!self.a)self.a=!alert(/XSS/)//&width&height

Provided and/or discovered by:
Ryuzaki Lawlet / Fahmi Fisal @justryuz

Postingan terkait:

Belum ada tanggapan untuk "Wordpress Theme - Adsense-id <== XSS"

Post a Comment