Headline
Online Birth Certificate Management System 1.0 Cross Site Scripting
Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
Online Birth Certificate Management System 1.0 Cross Site Scripting
Posted Sep 27, 2022
Authored by Yousef Alraddadi
Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
tags | exploit, xss
SHA-256 | 7e9852e1ba3b10ed9809857eace8d6e330d1f9d7306d8b2d80c0851d85229f86
Download | Favorite | View
Online Birth Certificate Management System 1.0 Cross Site Scripting
# Exploit Title: Online Birth Certificate Management System - Stored Cross-Site Scripting (XSS)# Google Dork: N/A# Date: 2022-9-27# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip# Tested on: windows 11 - XAMPP# CVE : N/A# Version: 1.0Vulnerability Details======================Steps :1) Log in to the application after register new userUsername: testPassword: 123452) Navigate to Birth Reg Form and Click on Add Details.3) add full name payload => <script>alert(document.cookie);</script>4) and all field enter payload only Contact Number enter number
File Tags
- ActiveX (932)
- Advisory (78,276)
- Arbitrary (15,276)
- BBS (2,859)
- Bypass (1,598)
- CGI (1,013)
- Code Execution (6,771)
- Conference (671)
- Cracker (799)
- CSRF (3,277)
- DoS (22,065)
- Encryption (2,340)
- Exploit (50,129)
- File Inclusion (4,160)
- File Upload (945)
- Firewall (821)
- Info Disclosure (2,565)
- Intrusion Detection (861)
- Java (2,823)
- JavaScript (808)
- Kernel (6,156)
- Local (14,093)
- Magazine (586)
- Overflow (12,252)
- Perl (1,413)
- PHP (5,057)
- Proof of Concept (2,284)
- Protocol (3,350)
- Python (1,406)
- Remote (29,862)
- Root (3,466)
- Ruby (581)
- Scanner (1,630)
- Security Tool (7,737)
- Shell (3,077)
- Shellcode (1,203)
- Sniffer (883)
- Spoof (2,123)
- SQL Injection (16,057)
- TCP (2,369)
- Trojan (682)
- UDP (872)
- Virus (660)
- Vulnerability (30,657)
- Web (9,114)
- Whitepaper (3,723)
- x86 (943)
- XSS (17,396)
- Other
File Archives
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- Older
Systems
- AIX (426)
- Apple (1,899)
- BSD (369)
- CentOS (55)
- Cisco (1,915)
- Debian (5,948)
- Fedora (1,690)
- FreeBSD (1,242)
- Gentoo (4,207)
- HPUX (878)
- iOS (323)
- iPhone (108)
- IRIX (220)
- Juniper (67)
- Linux (42,923)
- Mac OS X (684)
- Mandriva (3,105)
- NetBSD (255)
- OpenBSD (478)
- RedHat (12,009)
- Slackware (941)
- Solaris (1,607)
- SUSE (1,444)
- Ubuntu (8,027)
- UNIX (9,115)
- UnixWare (185)
- Windows (6,473)
- Other