Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2015-3440

Description

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

POC

Reference

- http://packetstormsecurity.com/files/131644/WordPress-4.2-Cross-Site-Scripting.html

- http://seclists.org/fulldisclosure/2015/Apr/84

- https://klikki.fi/adv/wordpress2.html

- https://wpvulndb.com/vulnerabilities/7945

- https://www.exploit-db.com/exploits/36844/

Github

- https://github.com/0v3rride/Week-7

- https://github.com/20142995/nuclei-templates

- https://github.com/AAp04/Codepath-Week-7

- https://github.com/AAp04/WordPress-Pen-Testing

- https://github.com/ARPSyndicate/cvemon

- https://github.com/Afetter618/WordPress-PenTest

- https://github.com/Cng000/web_sec_WK7

- https://github.com/Daas335b/Codepath.week7

- https://github.com/Daas335b/Week-7

- https://github.com/DinorahGV02/Codepath_Unit-7-Project-WordPress-vs.-Kali

- https://github.com/GianfrancoLeto/CodepathWeek7

- https://github.com/JamesNornand/CodePathweek7

- https://github.com/KushanSingh/Codepath-Project7

- https://github.com/Lukanite/CP_wpvulns

- https://github.com/MXia000/WordPress_Pentesting

- https://github.com/Rahul150811/Wordpress-vs-Kali

- https://github.com/XiaoyanZhang0999/WordPress_presenting

- https://github.com/YemiBeshe/Codepath-WP1

- https://github.com/alem-m/WordPressVSKali

- https://github.com/alvarezpj/websecurity-week7

- https://github.com/and-aleksandrov/wordpress

- https://github.com/beelzebielsk/csc59938-week-7

- https://github.com/cflor510/Wordpress-

- https://github.com/choyuansu/Week-7-Project

- https://github.com/dayanaclaghorn/codepathWP

- https://github.com/dkohli23/WordPressLab7and8

- https://github.com/drsh0x2/WebSec-Week7

- https://github.com/hpatelcode/codepath-web-security-week-7

- https://github.com/j5inc/week7

- https://github.com/jk-cybereye/codepath-week7

- https://github.com/jlangdev/WPvsKali

- https://github.com/joshuamoorexyz/exploits

- https://github.com/jr-333/week7

- https://github.com/kehcat/CodePath-Fall

- https://github.com/kevinsinclair83/Week-7

- https://github.com/kjtlgoc/CodePath-Unit-7-8-WordPress-Pentesting

- https://github.com/krushang598/Cybersecurity-Week-7-and-8

- https://github.com/lqiu1127/Codepath-wordpress-exploits

- https://github.com/mattdegroff/CodePath_Wk7

- https://github.com/nke5ka/codepathWeek7

- https://github.com/notmike/WordPress-Pentesting

- https://github.com/oleksandrbi/CodePathweek7

- https://github.com/preritpathak/Pentesting-live-targets-2

- https://github.com/rlucus/codepath

- https://github.com/theawkwardchild/WordPress-Pentesting

- https://github.com/w3bcooki3/Wordpress-vs-Kali

- https://github.com/zakia00/Week7Lab

- https://github.com/zjasonshen/CodepathWebSecurityWeek7

- https://github.com/zmh68/codepath-w07