.. / CVE-2017-14622

Exploit for WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scripting (CVE-2017-14622)

Description:

WordPress 2kb Amazon Affiliates Store plugin before 2.1.1 contains multiple cross-site scripting vulnerabilities. The plugin allows an attacker to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php, thus making possible theft of cookie-based authentication credentials and launch of other attacks.

Nuclei Template

View the template here CVE-2017-14622.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2017/CVE-2017-14622.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14622
https://packetstormsecurity.com/files/144261/WordPress-2kb-Amazon-Affiliates-Store-2.1.0-Cross-Site-Scripting.html
https://wordpress.org/plugins/2kb-amazon-affiliates-store/#developers
https://nvd.nist.gov/vuln/detail/CVE-2017-14622