[wp-trac] [WordPress Trac] #20593: wordpress 3.3.2 clickjacking

WordPress Trac wp-trac at lists.automattic.com
Tue May 1 19:06:25 UTC 2012


#20593: wordpress 3.3.2 clickjacking
--------------------------+-----------------------------
 Reporter:  abysssec      |      Owner:
     Type:  defect (bug)  |     Status:  new
 Priority:  normal        |  Milestone:  Awaiting Review
Component:  Gallery       |    Version:
 Severity:  critical      |   Keywords:
--------------------------+-----------------------------
 Wordpress Admin panel has x-frame-option which prevent clickjacking but in
 main page of blog no x-frame-option has been set, so it possible to trick
 him and make him to post a comment, using Clickjacking. As you may know
 admin can post comment with html and it is obvious by default this isn't
 dangerous, But as blog main page has no x-frame-option it is possible to
 make XSS of it and finally you can mix ClickJacking /XSS / HTTPOnly
 Disclosure to make a working exploit.

 here is video of  PoC :

 http://www.sendspace.com/file/60wxge

 here is PoC :

 http://www.sendspace.com/file/o754pt

 thanks Abysssec Team

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/20593>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list