
39 changes to exploits/shellcodes/ghdb ProLink PRS1841 PLDT Home fiber - Default Password Nacos 2.0.3 - Access Control vulnerability sudo 1.8.0 to 1.9.12p1 - Privilege Escalation sleuthkit 4.11.1 - Command Injection Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS) ManageEngin AMP 4.3.0 - File-path-traversal SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS) AmazCart CMS 3.4 - Cross-Site-Scripting (XSS) Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS) Art Gallery Management System Project v1.0 - SQL Injection (sqli) authenticated Art Gallery Management System Project v1.0 - SQL Injection (sqli) Unauthenticated ChiKoi v1.0 - SQL Injection ERPGo SaaS 3.9 - CSV Injection GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE) GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion GLPI v10.0.1 - Unauthenticated Sensitive Data Exposure GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration) Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS) MyBB 1.8.32 - Remote Code Execution (RCE) (Authenticated) Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute Prizm Content Connect v10.5.1030.8315 - XXE SLIMSV 9.5.2 - Cross-Site Scripting (XSS) WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS) Roxy WI v6.1.0.0 - Improper Authentication Control Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload Solaris 10 libXm - Buffer overflow Local privilege escalation Chromacam 4.0.3.0 - PsyFrameGrabberService Unquoted Service Path Grand Theft Auto III/Vice City Skin File v1.1 - Buffer Overflow HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path Windows 11 10.0.22000 - Backup service Privilege Escalation Windows/x86 - Create Administrator User / Dynamic PEB & EDT method null-free Shellcode (373 bytes)
30 lines
No EOL
1 KiB
Text
30 lines
No EOL
1 KiB
Text
# Exploit Title: AmazCart CMS 3.4 - Cross-Site-Scripting (XSS)
|
|
# Date: 17/01/2023
|
|
# Exploit Author: Sajibe Kanti
|
|
# Vendor Name: CodeThemes
|
|
# Vendor Homepage: https://spondonit.com/
|
|
# Software Link: https://codecanyon.net/item/amazcart-laravel-ecommerce-system-cms/34962179
|
|
# Version: 3.4
|
|
# Tested on: Live Demo
|
|
# Demo Link : https://amazy.rishfa.com/
|
|
|
|
# Description #
|
|
|
|
AmazCart - Laravel Ecommerce System CMS 3.4 is vulnerable to Reflected
|
|
cross-site scripting because of insufficient user-supplied data
|
|
sanitization. Anyone can submit a Reflected XSS payload without login in
|
|
when searching for a new product on the search bar. This makes the
|
|
application reflect our payload in the frontend search ber, and it is fired
|
|
everything the search history is viewed.
|
|
|
|
# Proof of Concept (PoC) : Exploit #
|
|
|
|
1) Goto: https://amazy.rishfa.com/
|
|
2) Enter the following payload in 'Search Iteam box' :
|
|
"><script>alert(1)</script>
|
|
3) Now You Get a Popout as Alert 1
|
|
4) Reflected XSS payload is fired
|
|
|
|
# Image PoC : Reference Image #
|
|
|
|
1) Payload Fired: https://prnt.sc/QQaiZB3tFMVB |