Release date:
Updated on: 2013-02-20
Affected Systems:
WordPress Responsive Logo Slideshow
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58013
CVE (CAN) ID: CVE-2013-1759
WordPress Responsive Logo Slideshow is a WordPress Slideshow that displays customer logos with links.
WordPress Responsive Logo Slideshow has the reflective/storage XSS vulnerability in the URL and Image input boxes. If malicious users control logon creden,, they can use these input fields to store malicious scripts, this causes unauthorized database operations.
<* Source: Aditya Balapure
Link: http://packetstormsecurity.com/files/120379/WordPress-Responsive-Logo-Slideshow-Cross-Site-Scripting.html
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
##########################
XSS location
URL and Image input box.
Script Used-
'; Alert (String. fromCharCode (88,83, 83) //'; alert (String. fromCharCode (88,83, 83 ))//";
Alert (String. fromCharCode (88,83, 83) // "; alert (String. fromCharCode (88,83, 83 ))//--
> </SCRIPT> "> '> <SCRIPT> alert (String. fromCharCode (88,83, 83) </SCRIPT>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://wordpress.org/support/view/plugin-reviews/responsive-logo-slideshow