mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
1.8 KiB
1.8 KiB
CVE-2017-6814
Description
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.
POC
Reference
- http://openwall.com/lists/oss-security/2017/03/06/8
- https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
- https://wpvulndb.com/vulnerabilities/8765
Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Afetter618/WordPress-PenTest
- https://github.com/CamHoo/WordPress-Pen-Testing-Lab
- https://github.com/Gshack18/WPS_Scan
- https://github.com/HarryMartin001/WordPress-vs.-Kali-Week-7-8
- https://github.com/MXia000/WordPress_Pentesting
- https://github.com/PatyRey/Codepath-WordPress-Pentesting
- https://github.com/XiaoyanZhang0999/WordPress_presenting
- https://github.com/alexanderkoz/Web-Security-Week-7-Project-WordPress-vs.-Kali
- https://github.com/ftruncale/Codepath-Week-7
- https://github.com/hughiednguyen/cybersec_kali_vs_old_wp_p7
- https://github.com/mattdegroff/CodePath_Wk7
- https://github.com/notmike/WordPress-Pentesting
- https://github.com/timashana/WordPress-Pentesting
- https://github.com/vkril/Cybersecurity-Week-7-Project-WordPress-vs.-Kali
- https://github.com/zmh68/codepath-w07
- https://github.com/zyeri/wordpress-pentesting