CVE-2015-8350: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS

CVE-2015-8350: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS-渗透云记 - 专注于网络安全与技术分享
CVE-2015-8350: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2015-8350: wordpress Calls to Action <=2.4.3 – Authenticated Reflected xss

漏洞描述

Calls to Action plugin before 2.5.1 for WordPress contains stored XSS caused by unsanitized input in open-tab parameter in wp-admin/edit.php and wp-cta-variation-id parameter in ab-testing-call-to-action-example/, letting remote attackers inject arbitrary web script or HTML, exploit requires sending crafted requests.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享