Aerosol Posted December 10, 2014 Report Posted December 10, 2014 *CVE-2014-8751 goYWP WebPress Multiple XSS (Cross-Site Scripting) SecurityVulnerabilities*Exploit Title: goYWP WebPress Multiple XSS (Cross-Site Scripting) SecurityVulnerabilitiesProduct: WebPressVendor: goYWPVulnerable Versions: 13.00.06Tested Version: 13.00.06Advisory Publication: Dec 09, 2014Latest Update: Dec 09, 2014Vulnerability Type: Cross-Site Scripting [CWE-79]CVE Reference: CVE-2014-8751Credit: Wang Jing [SPMS, Nanyang Technological University, Singapore]*Advisory Details:**(1) Product*"WebPress is the foundation on which we build web sites. It’s our uniqueContent Management System (CMS), flexible enough for us to build your dreamsite, and easy enough for you to maintain it yourself."*(2) Vulnerability Details:*goYWP WebPress is vulnerable to XSS attacks.*(2.1)* The first security vulnerability occurs at "/search.php" page with"&search_param" parameter in HTTP GET.*(2.2)* The second security vulnerability occurs at "/forms.php" (formsubmission ) page with "&name", "&address" "&comment" parameters in HTTPPOST.*References:*http://tetraph.com/security/cves/cve-2014-8751-goywp-webpress-multiple-xss-cross-site-scripting-security-vulnerabilities/http://www.goywp.com/view/cmshttp://www.goywp.com/demo.phphttp://cwe.mitre.orghttp://cve.mitre.org/Source Quote