Security
Headlines
HeadlinesLatestCVEs

Headline

Online Birth Certificate Management System 1.0 Cross Site Scripting

Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby

Online Birth Certificate Management System 1.0 Cross Site Scripting

Posted Sep 27, 2022

Authored by Yousef Alraddadi

Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss

SHA-256 | 7e9852e1ba3b10ed9809857eace8d6e330d1f9d7306d8b2d80c0851d85229f86

Download | Favorite | View

Online Birth Certificate Management System 1.0 Cross Site Scripting

# Exploit Title: Online Birth Certificate Management System - Stored Cross-Site Scripting (XSS)# Google Dork: N/A# Date: 2022-9-27# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip# Tested on: windows 11 - XAMPP# CVE : N/A# Version: 1.0Vulnerability Details======================Steps :1) Log in to the application after register new userUsername: testPassword: 123452) Navigate to Birth Reg Form and Click on Add Details.3) add full name payload => <script>alert(document.cookie);</script>4) and all field enter payload only Contact Number enter number

File Tags

  • ActiveX (932)
  • Advisory (78,276)
  • Arbitrary (15,276)
  • BBS (2,859)
  • Bypass (1,598)
  • CGI (1,013)
  • Code Execution (6,771)
  • Conference (671)
  • Cracker (799)
  • CSRF (3,277)
  • DoS (22,065)
  • Encryption (2,340)
  • Exploit (50,129)
  • File Inclusion (4,160)
  • File Upload (945)
  • Firewall (821)
  • Info Disclosure (2,565)
  • Intrusion Detection (861)
  • Java (2,823)
  • JavaScript (808)
  • Kernel (6,156)
  • Local (14,093)
  • Magazine (586)
  • Overflow (12,252)
  • Perl (1,413)
  • PHP (5,057)
  • Proof of Concept (2,284)
  • Protocol (3,350)
  • Python (1,406)
  • Remote (29,862)
  • Root (3,466)
  • Ruby (581)
  • Scanner (1,630)
  • Security Tool (7,737)
  • Shell (3,077)
  • Shellcode (1,203)
  • Sniffer (883)
  • Spoof (2,123)
  • SQL Injection (16,057)
  • TCP (2,369)
  • Trojan (682)
  • UDP (872)
  • Virus (660)
  • Vulnerability (30,657)
  • Web (9,114)
  • Whitepaper (3,723)
  • x86 (943)
  • XSS (17,396)
  • Other

File Archives

  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • Older

Systems

  • AIX (426)
  • Apple (1,899)
  • BSD (369)
  • CentOS (55)
  • Cisco (1,915)
  • Debian (5,948)
  • Fedora (1,690)
  • FreeBSD (1,242)
  • Gentoo (4,207)
  • HPUX (878)
  • iOS (323)
  • iPhone (108)
  • IRIX (220)
  • Juniper (67)
  • Linux (42,923)
  • Mac OS X (684)
  • Mandriva (3,105)
  • NetBSD (255)
  • OpenBSD (478)
  • RedHat (12,009)
  • Slackware (941)
  • Solaris (1,607)
  • SUSE (1,444)
  • Ubuntu (8,027)
  • UNIX (9,115)
  • UnixWare (185)
  • Windows (6,473)
  • Other

Packet Storm: Latest News

Ubuntu Security Notice USN-7089-6