Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-2714. PoCs published by hiphop.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the podPress WordPress plugin by injecting malicious JavaScript into the 'playerID' parameter of a SWF file. The payload triggers an alert box, proving arbitrary script execution in the context of the affected site.
Description
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the podPress WordPress plugin by injecting malicious JavaScript into the 'playerID' parameter of a SWF file. The payload triggers an alert box, proving arbitrary script execution in the context of the affected site.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N