Показать сообщение отдельно

  #3  
Старый 25.10.2012, 01:18
3ak.aT
Новичок
Регистрация: 01.12.2011
Сообщений: 0
С нами: 7604246

Репутация: 0
По умолчанию

Кто нибудь объяснит как раскрутить эту тему:

PHP код:
[COLOR="#000000"][COLOR="#0000BB"][/COLOR][COLOR="#FF8000"]###################################################################################



# Exploit Title: wordpress Count per Day Cross Site Scripting Vulnerability

#

# Google Dork:inurl:/wp-content/plugins/count-per-day

#

# Date: 08/24/2012

#

# Author: Crim3R

#

# Version 3.2.3

#

# Vendor Home : http://downloads.wordpress.org/plugin/count-per-day.3.2.3.zip

#

# Tested on: all

#

###################################################################################



[/COLOR][COLOR="#007700"]$

$[/
COLOR][COLOR="#0000BB"]Author will be not responsible[/COLOR][COLOR="#007700"]for[/COLOR][COLOR="#0000BB"]any damage[/COLOR][COLOR="#007700"].

$

[/
COLOR][COLOR="#FF8000"]###################################################################################





[/COLOR][COLOR="#007700"]========================================

[/
COLOR][COLOR="#0000BB"]first notes[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]php is not restricted to admin[/COLOR][COLOR="#007700"]and[/COLOR][COLOR="#0000BB"]anyone can access it directty by

browser
[/COLOR][COLOR="#007700"]=>[/COLOR][COLOR="#0000BB"]an attacker can add notes witch



can be html codes
[/COLOR][COLOR="#007700"]=>[/COLOR][COLOR="#0000BB"]its Stored Xss

[/COLOR][COLOR="#007700"]goto[/COLOR][COLOR="#0000BB"]WP[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]path[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]wp[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]content[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]plugins[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]count[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]per[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]day[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]notes[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]php

in the notes section add html code
[/COLOR][COLOR="#007700"]and[/COLOR][COLOR="#0000BB"]click Add

D3M0
[/COLOR][COLOR="#007700"]:

[/COLOR][COLOR="#0000BB"]http[/COLOR][COLOR="#007700"]:[/COLOR][COLOR="#FF8000"]//www.christinedesavino.com/blog/wp-content/plugins/count-per-day



[/COLOR][COLOR="#0000BB"]http[/COLOR][COLOR="#007700"]:[/COLOR][COLOR="#FF8000"]//www.dhakadakshinghsc.com/wp-content/plugins/count-per-day/



[/COLOR][COLOR="#0000BB"]www[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]watansport[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]net[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]ara[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]wp[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]content[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]plugins[/COLOR][COLOR="#007700"]/[/COLOR][COLOR="#0000BB"]count[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]per[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]day[/COLOR][COLOR="#007700"]/





===============[/COLOR][COLOR="#0000BB"]Crim3R[/COLOR][COLOR="#007700"]@[/COLOR][COLOR="#0000BB"]Att[/COLOR][COLOR="#007700"].[/COLOR][COLOR="#0000BB"]Net[/COLOR][COLOR="#007700"]===========



[/COLOR][COLOR="#0000BB"]$home[/COLOR][COLOR="#007700"]= %[/COLOR][COLOR="#0000BB"]00

thanks to
[/COLOR][COLOR="#007700"]:[/COLOR][COLOR="#0000BB"]2MzRp[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]Mikili[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]0x0ptim0us[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]iC0d3R[/COLOR][COLOR="#007700"]-[/COLOR][COLOR="#0000BB"]farbodmahini[/COLOR][COLOR="#007700"]&[/COLOR][COLOR="#0000BB"]Amir

[/COLOR][/COLOR
 
Ответить с цитированием