CVE-2014-5345
Disqus Comment System < 2.76 - Cross-Site Scripting via Upgrade Step Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5345.
AI-analyzed exploit summary This is a functional proof-of-concept for a CSRF and stored XSS vulnerability in the Disqus for WordPress plugin up to version 2.7.5. The exploit uses a hidden form with malicious input to trigger the vulnerability when loaded.
Description
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
Exploits (1)
This is a functional proof-of-concept for a CSRF and stored XSS vulnerability in the Disqus for WordPress plugin up to version 2.7.5. The exploit uses a hidden form with malicious input to trigger the vulnerability when loaded.