.. / CVE-2011-4624

Exploit for GRAND FlAGallery 1.57 - Cross-Site Scripting (CVE-2011-4624)

Description:

A cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

Nuclei Template

View the template here CVE-2011-4624.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2011/CVE-2011-4624.yaml
Copy

References:

http://www.openwall.com/lists/oss-security/2011/12/23/2
http://wordpress.org/extend/plugins/flash-album-gallery/changelog/
https://github.com/ARPSyndicate/kenzer-templates
http://plugins.trac.wordpress.org/changeset/469785
https://nvd.nist.gov/vuln/detail/CVE-2011-4624