### [CVE-2015-3440](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3440) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. ### POC #### Reference - http://packetstormsecurity.com/files/131644/WordPress-4.2-Cross-Site-Scripting.html - http://seclists.org/fulldisclosure/2015/Apr/84 - https://klikki.fi/adv/wordpress2.html - https://wpvulndb.com/vulnerabilities/7945 - https://www.exploit-db.com/exploits/36844/ #### Github - https://github.com/0v3rride/Week-7 - https://github.com/AAp04/Codepath-Week-7 - https://github.com/AAp04/WordPress-Pen-Testing - https://github.com/ARPSyndicate/cvemon - https://github.com/Afetter618/WordPress-PenTest - https://github.com/Cng000/web_sec_WK7 - https://github.com/Daas335b/Codepath.week7 - https://github.com/Daas335b/Week-7 - https://github.com/DinorahGV02/Codepath_Unit-7-Project-WordPress-vs.-Kali - https://github.com/GianfrancoLeto/CodepathWeek7 - https://github.com/JamesNornand/CodePathweek7 - https://github.com/KushanSingh/Codepath-Project7 - https://github.com/Lukanite/CP_wpvulns - https://github.com/MXia000/WordPress_Pentesting - https://github.com/Rahul150811/Wordpress-vs-Kali - https://github.com/XiaoyanZhang0999/WordPress_presenting - https://github.com/YemiBeshe/Codepath-WP1 - https://github.com/alem-m/WordPressVSKali - https://github.com/alvarezpj/websecurity-week7 - https://github.com/and-aleksandrov/wordpress - https://github.com/beelzebielsk/csc59938-week-7 - https://github.com/cflor510/Wordpress- - https://github.com/choyuansu/Week-7-Project - https://github.com/dayanaclaghorn/codepathWP - https://github.com/dkohli23/WordPressLab7and8 - https://github.com/drsh0x2/WebSec-Week7 - https://github.com/hpatelcode/codepath-web-security-week-7 - https://github.com/j5inc/week7 - https://github.com/jk-cybereye/codepath-week7 - https://github.com/jlangdev/WPvsKali - https://github.com/joshuamoorexyz/exploits - https://github.com/jr-333/week7 - https://github.com/kehcat/CodePath-Fall - https://github.com/kevinsinclair83/Week-7 - https://github.com/kjtlgoc/CodePath-Unit-7-8-WordPress-Pentesting - https://github.com/krushang598/Cybersecurity-Week-7-and-8 - https://github.com/lqiu1127/Codepath-wordpress-exploits - https://github.com/mattdegroff/CodePath_Wk7 - https://github.com/nke5ka/codepathWeek7 - https://github.com/notmike/WordPress-Pentesting - https://github.com/oleksandrbi/CodePathweek7 - https://github.com/preritpathak/Pentesting-live-targets-2 - https://github.com/rlucus/codepath - https://github.com/theawkwardchild/WordPress-Pentesting - https://github.com/zakia00/Week7Lab - https://github.com/zjasonshen/CodepathWebSecurityWeek7 - https://github.com/zmh68/codepath-w07