WordPress Contact Form 7 Integrations Plugin Multiple Cross Site Scripting Vulnerabilities
BID:70196
Info
WordPress Contact Form 7 Integrations Plugin Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 70196 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6445 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2014 12:00AM |
| Updated: | Sep 26 2014 12:00AM |
| Credit: | g0blin |
| Vulnerable: |
Contactus contact form 7 integrations 1.3.10 Contactus contact form 7 integrations 1.3.9 Contactus contact form 7 integrations 1.3.8 Contactus contact form 7 integrations 1.3.7 Contactus contact form 7 integrations 1.3.6 Contactus contact form 7 integrations 1.3.5 Contactus contact form 7 integrations 1.3.4 Contactus contact form 7 integrations 1.3.3 Contactus contact form 7 integrations 1.3.2 Contactus contact form 7 integrations 1.3.1 Contactus contact form 7 integrations 1.3 |
| Not Vulnerable: |
Contactus contact form 7 integrations 1.3.11 |
Discussion
WordPress Contact Form 7 Integrations Plugin Multiple Cross Site Scripting Vulnerabilities
The Contact Form 7 Integrations plugin for WordPress is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Contact Form 7 Integrations 1.0 through 1.3.10 are vulnerable.
The Contact Form 7 Integrations plugin for WordPress is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Contact Form 7 Integrations 1.0 through 1.3.10 are vulnerable.
Exploit / POC
WordPress Contact Form 7 Integrations Plugin Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/wp-content/plugins/contact-form-7-integrations/includes/toAdmin.php?uE=1&uC=');alert('testing');</script>
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/wp-content/plugins/contact-form-7-integrations/includes/toAdmin.php?uE=1&uC=');alert('testing');</script>
References
WordPress Contact Form 7 Integrations Plugin Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Contact Form 7 Integrations Homepage (Contactus)
- WordPress HomePage (WordPress)