2.6
CVSSv2

CVE-2012-5349

Published: 09/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin prior to 1.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress pay-with-tweet

Exploits

# Exploit Title: Wordpress Pay With Tweet plugin <= 11 Multiple Vulnerabilities # Date: 01/06/2012 # Author: Gianluca Brindisi (gATbrindisi @gbrindisi brindisi/g/) # Software Link: downloadswordpressorg/plugin/pay-with-tweet11zip # Version: 11 1) Blind SQL Injection in shortcode: Short code parameter 'id' is prone to ...