[] NeoSense

WordPress Plugin Count Per Day 3.2.3 - Cross-Site Scripting

Author: Crim3R
type: webapps
platform: php
port: 
date_added: 2012-08-27 
date_updated: 2016-10-30 
verified: 1 
codes: OSVDB-84933 
tags: WordPress Plugin
aliases:  
screenshot_url: http://www.exploit-db.com/screenshots/idlt21000/screen-shot-2012-08-27-at-101246-am.png 
application_url: http://www.exploit-db.comcount-per-day.3.2.3.zip

###################################################################################

# Exploit Title: wordpress Count per Day Cross Site Scripting Vulnerability
#
# Google Dork:inurl:/wp-content/plugins/count-per-day
#
# Date: 08/24/2012
#
# Author: Crim3R
#
# Version 3.2.3
#
# Vendor Home : http://downloads.wordpress.org/plugin/count-per-day.3.2.3.zip
#
# Tested on: all
#
###################################################################################

$
$        Author will be not responsible for any damage.
$
###################################################################################


========================================
first notes.php is not restricted to admin and anyone can access it directty by
browser => an attacker can add notes witch

can be html codes => its Stored Xss
goto WP-path/wp-content/plugins/count-per-day/notes.php
in the notes section add html code and click Add
D3M0 :
http://www.christinedesavino.com/blog/wp-content/plugins/count-per-day

http://www.dhakadakshinghsc.com/wp-content/plugins/count-per-day/

www.watansport.net/ara/wp-content/plugins/count-per-day/


===============Crim3R@Att.Net===========

$home = %00
thanks to :  2MzRp - Mikili - 0x0ptim0us - iC0d3R - farbodmahini & Amir