
39 changes to exploits/shellcodes/ghdb ProLink PRS1841 PLDT Home fiber - Default Password Nacos 2.0.3 - Access Control vulnerability sudo 1.8.0 to 1.9.12p1 - Privilege Escalation sleuthkit 4.11.1 - Command Injection Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS) ManageEngin AMP 4.3.0 - File-path-traversal SQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS) AmazCart CMS 3.4 - Cross-Site-Scripting (XSS) Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS) Art Gallery Management System Project v1.0 - SQL Injection (sqli) authenticated Art Gallery Management System Project v1.0 - SQL Injection (sqli) Unauthenticated ChiKoi v1.0 - SQL Injection ERPGo SaaS 3.9 - CSV Injection GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE) GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion GLPI v10.0.1 - Unauthenticated Sensitive Data Exposure GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration) Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS) MyBB 1.8.32 - Remote Code Execution (RCE) (Authenticated) Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection pimCore v5.4.18-skeleton - Sensitive Cookie with Improper SameSite Attribute Prizm Content Connect v10.5.1030.8315 - XXE SLIMSV 9.5.2 - Cross-Site Scripting (XSS) WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS) Roxy WI v6.1.0.0 - Improper Authentication Control Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload Solaris 10 libXm - Buffer overflow Local privilege escalation Chromacam 4.0.3.0 - PsyFrameGrabberService Unquoted Service Path Grand Theft Auto III/Vice City Skin File v1.1 - Buffer Overflow HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path Microsoft Exchange Active Directory Topology 15.02.1118.007 - 'Service MSExchangeADTopology' Unquoted Service Path Windows 11 10.0.22000 - Backup service Privilege Escalation Windows/x86 - Create Administrator User / Dynamic PEB & EDT method null-free Shellcode (373 bytes)
51 lines
No EOL
1.8 KiB
Text
51 lines
No EOL
1.8 KiB
Text
# Exploit Title: Active eCommerce CMS 6.5.0 - Stored Cross-Site Scripting (XSS)
|
|
# Date: 19/01/2023
|
|
# Exploit Author: Sajibe Kanti
|
|
# Vendor Name: ActiveITzone
|
|
# Vendor Homepage: https://activeitzone.com/
|
|
# Software Link: https://codecanyon.net/item/active-ecommerce-cms/23471405
|
|
# Version: 6.5.0
|
|
# Tested on: Live ( Centos & Litespeed Web Server)
|
|
# Demo Link : https://demo.activeitzone.com/ecommerce/
|
|
|
|
# Description #
|
|
|
|
The Active eCommerce CMS 6.5.0 application has a vulnerability in the
|
|
profile picture upload feature that allows for stored cross-site scripting
|
|
(XSS) attacks. Specifically, the vulnerability lies in the handling of
|
|
"svg" image files, which can contain malicious code. An attacker can
|
|
exploit this vulnerability by uploading a specially crafted "svg" image
|
|
file as a profile picture, which will then be executed by the application
|
|
when the user views the profile. This can allow the attacker to steal
|
|
sensitive information, such as login credentials, or to perform other
|
|
malicious actions on the user's behalf. This vulnerability highlights the
|
|
importance of proper input validation and image file handling in web
|
|
application development.
|
|
|
|
# Exploit Details #
|
|
|
|
# Vulnerable Path : /aiz-uploader/upload
|
|
# Parameter: files (POST)
|
|
# Vector: <svg version="1.1" baseProfile="full" xmlns="
|
|
http://www.w3.org/2000/svg">
|
|
<rect width="300" height="100"
|
|
style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
|
|
<script type="text/javascript">
|
|
alert("haha XSS");
|
|
</script>
|
|
</svg>
|
|
|
|
# Proof of Concept (PoC) : Exploit #
|
|
|
|
1) Goto: https://localhost
|
|
2) Click Registration
|
|
3) Login Your Account
|
|
4) Go Manage Profile
|
|
5) Now Upload Given Vector as anyname.svg (you must put vector code in
|
|
anyname.svg file)
|
|
6) After Upload Clic to view Your profile picture
|
|
7) XSS Popup Will Fired
|
|
|
|
# Image PoC : Reference Image #
|
|
|
|
1) Payload Fired: https://prnt.sc/cW0F_BtpyMcv |