CVE-2015-2755: WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting

CVE-2015-2755: WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2015-2755: WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2015-2755: wordpress AB Google Map Travel <=3.4 – Stored Cross-Site Scripting

漏洞描述

WordPress AB Google Map Travel plugin through 3.4 contains multiple stored cross-site scripting vulnerabilities. The plugin allows an attacker to hijack the administrator authentication for requests via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameters in the ab_map_options page to wp-admin/admin.php.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享