vendor:
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager
by:
8bitsec
8,8
CVSS
HIGH
Stored XSS and Blind SQL Injection
79 (XSS) and 89 (SQL Injection)
CWE
Product Name: Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager
Affected Version From: 3.4
Affected Version To: 3.4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0, Mac OS 10.12.6
2017
Ads Pro Plugin – Multi-Purpose WordPress Advertising Manager <= v3.4 - Stored XSS / SQLi
Multiple Stored XSS vulnerabilities were found in the Ad Title and Ad Description parameters of the Front End Order Form. The payload will execute when the ad is displayed. Blind SQL Injection was found on the bsa_pro_id parameter, with payloads of AND boolean-based blind - WHERE or HAVING clause and MySQL >= 5.0.12 AND time-based blind.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.