CVE-2013-2501
terillion_reviews_plugin < 1.1 - Cross-Site Scripting via ProfileId Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2501. PoCs published by Aditya Balapure.
AI-analyzed exploit summary This exploit demonstrates an HTML-injection vulnerability in the Terillion Reviews WordPress plugin. It includes multiple XSS payloads designed to execute arbitrary JavaScript in the context of the affected browser.
Description
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.
Exploits (1)
This exploit demonstrates an HTML-injection vulnerability in the Terillion Reviews WordPress plugin. It includes multiple XSS payloads designed to execute arbitrary JavaScript in the context of the affected browser.