[+] Exploit Title ; Holo Link Box Multiple vulnerability
[+] Date : 2018-01-30
[+] Author : 0P3N3R From IRANIAN ETHICAL HACKERS
[+] Version : 1.1
[+] Vendor Homepage :
[+] Dork :
[+] Forum : irethicalhackers.com/forums
[+] Tested On : windows 10 - kali linux 2.0
[+] Contact : https://telegram.me/WebServer
[+] Description :
[!] Holo Is a link box And Users can submit any sites link
[!] This script was updated a month ago
[!] But there are a lot of problems in this script
[+] Poc :
[1] Stored XSS Vulnerability :
[!] Go to submit new link And insert payload on link title and link description.
[!] now click on submit button and go menu of manage links
[!] now you can see Stord xss
[*] Payload : <script>alert(String.fromCharCode(88, 83, 83))</script>
[2] login to admin panel without entering password :
[!]you can login to the admin panel without entering password if you follow this link
[!] http://localhost/holoscript/manage/
[3] Remove the link without access to the admin panel :
[!] You can delete submited links without accsess to admin panel. For Ex :
[!] http://localhost/pic/manage/ManageLink.php?do=ban&id=5
[!] Change the id to remove any link on the website
[+] Security Level :
[!] High
[+] Exploitation Technique:
[!] Remote
[+] Vulnerability Files :
[*] ManageLink.php
[*] AddNew.php
[*] ReceiveLink.php
[+] Fix :
[!] Restrict user input or replace bad characters And Secure adminpanel
[+] We Are : [+] 0P3N3R [+] Mehrdad_Ice [+] BaxTurk24 [+] S0hp [+] ERROR1067