CVE-2013-1463
WP-Table Reloaded < 1.9.4 - Cross-Site Scripting via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-1463. PoCs published by hiphop.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the WP-Table Reloaded WordPress plugin by injecting malicious input into the 'id' parameter of the zeroclipboard.swf file. The payload triggers an alert dialog, confirming the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be the same vulnerability as CVE-2013-1808. If so, it is likely that CVE-2013-1463 will be REJECTed.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the WP-Table Reloaded WordPress plugin by injecting malicious input into the 'id' parameter of the zeroclipboard.swf file. The payload triggers an alert dialog, confirming the vulnerability.