[+] Exploit Title ; Automatic Link Box CMS cross site scripting (stored) vulnerability
[+] Date : 2018-01-28
[+] Dork : intext:" System Powered By : Mehrdad Design "
[!] intext:" Template By : Mehrdad Design"
[+] Vendor HomePage : http://mehrdaddesign.com/
[+] Author : 0P3N3R From IRANIAN ETHICAL HACKERS
[+] Forum : irethicalhackers.com/forums
[+] Tested On : windows 10 - kali linux 2.0
[+] Contact : https://telegram.me/WebServer
[+] Poc :
[!] First Go to the admin panel and insert your payload on New Link Box
[!] Payload : <script>alert(String.fromCharCode(88, 83, 83))</script>
[!] now you can see 0P3N3R on on admin panel and site
[+] Security Level :
[!] low
[+] Exploitation Technique:
[!] local
[+] Vulnerability Files :
[*] links.add.php
[+] Fix :
[!] Restrict user input or replace bad characters or use htmlspecialchars and htmlentities
[+] We Are : [+] 0P3N3R [+] Mehrdad_Ice [+] BaxTurk24 [+] S0hp [+] ERROR1067