Exploit Bilboplanet 2.0 - Multiple Cross-Site Scripting Vulnerabilities

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
34089
Проверка EDB
  1. Пройдено
Автор
VIVEK N
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
null
Дата публикации
2014-07-16
Bilboplanet 2.0 - Multiple Cross-Site Scripting Vulnerabilities
Код:
# Exploit Title: Multiple XSS vulnerabilities in Bilboplanet application
# Date: 10/15/13
# Exploit Author:Vivek N
# (http://nvivek.weebly.com/)
# Vendor Homepage: http://www.bilboplanet.com/
# Software Link: www.bilboplanet.com/index.php/downloads/?lang=en
# Version: 2.0
# Tested on: Windows
# CVE :

    1. Stored  XSS Vulnerability when creating and updating tribes  in
             http://localhost/bilboplanet/user/?page=tribes
             POST Parameter: tribe_name
    2. Stored XSS vulnerability when adding tag
            http://localhost/bilboplanet/user/?page=tribes
            POST Parameter: tags
    3. Stored XSS in parameters : user_id and fullname
            http://127.0.0.1/bilboplanet/signup.php
 
Источник
www.exploit-db.com

Похожие темы