cve/2017/CVE-2017-6814.md

36 lines
1.8 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2017-6814](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6814)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.
### POC
#### Reference
- http://openwall.com/lists/oss-security/2017/03/06/8
- https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
- https://wpvulndb.com/vulnerabilities/8765
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Afetter618/WordPress-PenTest
- https://github.com/CamHoo/WordPress-Pen-Testing-Lab
- https://github.com/Gshack18/WPS_Scan
- https://github.com/HarryMartin001/WordPress-vs.-Kali-Week-7-8
- https://github.com/MXia000/WordPress_Pentesting
- https://github.com/PatyRey/Codepath-WordPress-Pentesting
- https://github.com/XiaoyanZhang0999/WordPress_presenting
- https://github.com/alexanderkoz/Web-Security-Week-7-Project-WordPress-vs.-Kali
- https://github.com/ftruncale/Codepath-Week-7
- https://github.com/hughiednguyen/cybersec_kali_vs_old_wp_p7
- https://github.com/mattdegroff/CodePath_Wk7
- https://github.com/notmike/WordPress-Pentesting
- https://github.com/timashana/WordPress-Pentesting
- https://github.com/vkril/Cybersecurity-Week-7-Project-WordPress-vs.-Kali
- https://github.com/zmh68/codepath-w07
- https://github.com/zyeri/wordpress-pentesting