Content Spoofing @ https://irclogs.wordpress.org/

Disclosed: 2017-12-04 08:02:35 By hackerwahab To wordpress
Low
Vulnerability Details
Hello, Greetings, Today I was Free So I Decided to Do Pentest WordPress So i Found a SubDomain which is Vulnerable to Plain text Content Spoofing. PoC:- Url:- https://irclogs.wordpress.org/chanlog.php?channel=wordpress&day=[Message Goes Here]&sort=asca Example:- https://irclogs.wordpress.org/chanlog.php?channel=wordpress&day=today%20is%20not%20found%20because%20Wordpress%20Is%20Currently%20Down%20Kindly%20Visit%20Phishing.com%20and%20Login%20with%20Your%20Account%20For%20Further%20Details.%20Regards,%20Wordpress%20Team.&sort=asca Thanks, Abdulwahab Khan, Independent Cyber Security Researcher
Actions
View on HackerOne
Report Stats
  • Report ID: 278151
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report