Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-8800. PoCs published by Kacper Szurek.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in Nextend Facebook Connect 1.4.59 due to improper input sanitization in the plugin settings update functionality. The PoC provides a form that submits malicious JavaScript payload via the 'fb_login_button' parameter, which is then stored and executed in the context of the application.
Description
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action.
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in Nextend Facebook Connect 1.4.59 due to improper input sanitization in the plugin settings update functionality. The PoC provides a form that submits malicious JavaScript payload via the 'fb_login_button' parameter, which is then stored and executed in the context of the application.