#Product : cm-ad-changer
#Exploit Author : Rahul Pratap Singh
#Version :1.7.2
#Home page Link : https://wordpress.org/plugins/
#Website : 0x62626262.wordpress.com
#Linkedin : https://in.linkedin.com/in/
#Date : 21/4/2016
XSS Vulnerability:
------------------------------
Description:
------------------------------
Following parameters are not sanitized that leads to XSS Vulnerability.
title, comment, link
------------------------------
Vulnerable Code:
------------------------------
File Name: testfiles/cm-ad-changer/
Found at line:61
<input type="checkbox" name="acs_active" id="acs_active" value="1" <?php
echo ($fields_data['acs_active'] == '1' ? 'checked=checked' : '') ?> />
Found at line:73
<textarea id="acs_custom_css" name="acs_custom_css" rows=7 value="<?php
echo stripslashes($fields_data['
stripslashes($fields_data['
File Name: testfiles/cm-ad-changer/
Found at line:96
<textarea value="<?php echo (isset($fields_data['comment']
stripslashes($fields_data['
id="comment"><?php echo (isset($fields_data['comment']
stripslashes($fields_data['
------------------------------
POC:
------------------------------
https://0x62626262.files.
https://0x62626262.files.
Fix:
Update to 1.7.6
Vulnerability Disclosure Timeline:
→ March 14, 2016 – Bug discovered, initial report to Vendor.
→ March 22, 2016 – No Response. Report sent again.
→ March 23, 2016 – WordPress Acknowledged.
→ April 21, 2016 – Full Disclosure.
Pub Ref:
https://0x62626262.wordpress.
https://ad-changer.cminds.com/
Komentarų nėra:
Rašyti komentarą