Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Ultimate Maps 1.2.4 Cross Site Scripting

https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
WordPress Ultimate Maps plugin version 1.2.4 suffers from a cross site scripting vulnerability.

MD5 | a15131838592d920ab537cfb27e37ab4

Download
# Exploit Title: WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
# Date: 3/28/2021
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/ultimate-maps-by-supsystic/
# Version: 1.2.4
# Tested on: Windows 10
# CVE: CVE-2021-24274

1. Description:
The plugin did not sanitize the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

2. Proof of Concept:
/wp-admin/admin.php?page=ultimate-maps-supsystic&tab="+style=animation-name:rotation+onanimationstart=alert(/XSS/)//

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Spectra HacktheBox Walkthrough

Today we are going to accept the boot2root challenge of Spectra –Hack the box lab. Through this lab, we are going to check our skills in WordPress Exploitation and basic privilege escalation. Table Of Content Reconnaissance Nmap Enumeration WordPress enumeration Exploitation WordPress Metasploit Privilege Escalation Abusing Sudo rights Reconnaissance Let’s

The post Spectra HacktheBox Walkthrough appeared first on Hacking Articles.

___________________________
@hacking_Attack
@Hacking_Video
My biggest dream — Ethical Hacking

When technologies started to come in our house I was a kid. These technologies include mobile, laptop and computer. The main focus was to…Continue reading on Medium »
Read more...
Why You Should Never Test Exploits on Mainnet or Public Testnets

Not everyone who moves from the Web2 security world into the Web3 space is aware of the most important, fundamental rule about blockchain…Continue reading on Immunefi »
Read more...
Exploiting Web cache deception(WCD)

next time I will talk about Combining Path confusion with Web cache deception.Continue reading on Medium »
Read more...
The boring side of testing people should be talking about more!

Continue reading on Medium »
Read more...