CVE-2008-0192
WordPress < 2.0.9 - Cross-Site Scripting via popuptitle Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-0192. PoCs published by 3APA3A.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in WordPress by injecting malicious JavaScript via the 'popuptitle' parameter in the post.php URL. The payload uses the 'expression' CSS property to execute arbitrary JavaScript, specifically an alert displaying the document cookie.
Description
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WordPress by injecting malicious JavaScript via the 'popuptitle' parameter in the post.php URL. The payload uses the 'expression' CSS property to execute arbitrary JavaScript, specifically an alert displaying the document cookie.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WordPress by injecting malicious JavaScript via the 'popuptitle' parameter in the page-new.php URL. The payload uses the 'expression' CSS property to execute arbitrary JavaScript, specifically an alert displaying the document cookie.