Lucene search

K
wpexploitEthicalhack3rWPEX-ID:DC337770-BB13-4F88-99AA-C7FA2D58E0FC
HistorySep 14, 2015 - 12:00 a.m.

PowerPress Podcasting < 6.0.5 - Authenticated Cross-Site Scripting (XSS)

2015-09-1400:00:00
ethicalhack3r
8

EPSS

0.001

Percentile

38.3%

By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged in user’s session by stealing cookies. This means that the malicious hacker can change the logged in user’s password and invalidate the session of the victim while the hacker maintains access.

1. Logon into any wordpress application (localhost or public host)
2. Modifying the value of tab variable in Blubrry PowerPress Version 6.0.4
3. Fill all the variables with "></script><script>alert(document.cookie);</script> payload and send the request to the server.
4. Now, the added XSS payload will be echoed back from the server without validating the input even after wp-config.php file has been configured with XSS filter settings.

EPSS

0.001

Percentile

38.3%

Related for WPEX-ID:DC337770-BB13-4F88-99AA-C7FA2D58E0FC