Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-14622 PoC — WordPress 2kb Amazon Affiliates Store插件跨站脚本漏洞

Source
Associated Vulnerability
Title:WordPress 2kb Amazon Affiliates Store插件跨站脚本漏洞 (CVE-2017-14622)
Description:WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。2kb Amazon Affiliates Store plugin是其中的一个亚马逊商店插件。 WordPress 2kb Amazon Affiliates Store插件2.1.1之前的版本中存在跨站脚本漏洞,该漏洞源于程序没有充分的验证用户提交的数据。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。
Description
WordPress 2kb Amazon Affiliates Store plugin before 2.1.1 contains multiple cross-site scripting vulnerabilities. The plugin allows an attacker to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php, thus making possible theft of cookie-based authentication credentials and launch of other attacks.
File Snapshot

id: CVE-2017-14622 info: name: WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scriptin ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.