###################### # Exploit Title : Wordpress blogstand-smart-banner.1.0 Cross Site Scripting # Exploit Author : Ashiyane Digital Security Team # Vendor Homepage : http://wordpress.org/plugins/blogstand-smart-banner/ # Software Link : http://downloads.wordpress.org/plugin/blogstand-smart-banner.1.0.zip # Date : 2014-06-28 # Tested on : Windows 7 / Mozilla Firefox ###################### # Location : http://localhost/wp-admin/options-general.php?page=bs-banner ###################### # Vulnerable code :