Vulnerability: Cross-site scripting WordPress Download Monitor
CVE ID: CVE-2012-4768
Impact: Cross Site Scripting
Affected products: WordPress Download Monitor Plugin 3.x
Affected versions: WordPress Download Monitor 3.3.5.7, possibly earlier.
Description:
The vulnerability allows malicious people to conduct XSS attacks.
The vulnerability is caused due to insufficient input validation in the parameter “dlsearch” in the script index.php (when the parameter “page_id” zeal id download page). This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.
Manufacturer URL: http://mikejolley.com/
Solution: Update to version 3.3.5.9 from the manufacturer.
links:
http://www.reactionpenetrationtesting.co.uk/wordpress-download-monitor-xss.html