Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2023-51504 PoC — WordPress Dan's Embedder for Google Calendar Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS)

Source
Associated Vulnerability
Title:WordPress Dan's Embedder for Google Calendar Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS) (CVE-2023-51504)
Description:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.
Description
This is a dockerized reproduction of the MotoCMS SQL injection (cf exploit db) 
Readme
# CVE-2023-51504
This is a dockerized reproduction of the MotoCMS SQL injection (cf exploit db) 

# Description
MotoCMS Version 3.4.3 SQL Injection via the keyword parameter on the link https://template189526.motopreview.com/store/category/search/?keyword=1

Reproducing the vulnerability involved defining (in a Dockerfile) the commands or instructions needed to reproduce a kali linux machine and run sqlmap in order to detect and display the results of the vulnerability.

To get the results, run the command 

```docker run -d sybelle20/cve-2023-51504:motocms-sqli```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →