Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-4768. PoCs published by Chris Cooper. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the Download Monitor WordPress plugin by injecting arbitrary JavaScript via the 'dlsearch' parameter. The PoC uses a simple alert payload to confirm the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the Download Monitor WordPress plugin by injecting arbitrary JavaScript via the 'dlsearch' parameter. The PoC uses a simple alert payload to confirm the vulnerability.
Nuclei Templates (1)
http.html:"/wp-content/plugins/download-monitor/"
body="/wp-content/plugins/download-monitor/"