exploit-db-mirror/exploits/php/webapps/34089.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

18 lines
No EOL
720 B
Text

# Exploit Title: Multiple XSS vulnerabilities in Bilboplanet application
# Date: 10/15/13
# Exploit Author:Vivek N
# (http://nvivek.weebly.com/)
# Vendor Homepage: http://www.bilboplanet.com/
# Software Link: www.bilboplanet.com/index.php/downloads/?lang=en
# Version: 2.0
# Tested on: Windows
# CVE :
1. Stored XSS Vulnerability when creating and updating tribes in
http://localhost/bilboplanet/user/?page=tribes
POST Parameter: tribe_name
2. Stored XSS vulnerability when adding tag
http://localhost/bilboplanet/user/?page=tribes
POST Parameter: tags
3. Stored XSS in parameters : user_id and fullname
http://127.0.0.1/bilboplanet/signup.php