mirror of
https://github.com/0xMarcio/cve.git
synced 2025-12-30 04:49:42 +00:00
845 B
845 B
CVE-2014-3842
Description
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.
POC
Reference
- http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.html
- http://seclists.org/fulldisclosure/2014/Apr/265
- http://www.exploit-db.com/exploits/33076
Github
No PoCs found on GitHub currently.