Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-2755 PoC — WordPress AB Google Map Travel插件跨站请求伪造漏洞

Source
Associated Vulnerability
Title:WordPress AB Google Map Travel插件跨站请求伪造漏洞 (CVE-2015-2755)
Description:WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。AB Google Map Travel(AB-MAP)是其中的一个通过谷歌地图显示起点到旅游地点之间的距离和行驶方向的插件。 WordPress AB-MAP插件4.0之前版本中存在跨站请求伪造漏洞,该漏洞源于wp-admin/admin.php脚本没有充分过滤ab_map_options页面中的多个参数(lat(Latitude),long(Longitude)
Description
WordPress AB Google Map Travel plugin through 3.4 contains multiple stored cross-site scripting vulnerabilities. The plugin allows an attacker to hijack the administrator authentication for requests via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameters in the ab_map_options page to wp-admin/admin.php.
File Snapshot

id: CVE-2015-2755 info: name: WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.