exploit-db-mirror/exploits/php/webapps/34555.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

18 lines
No EOL
489 B
Text

# Exploit Title: [phponlinechat xss ]
# Date: [5/9/2014]
# Exploit Author: [N0 Feel]
# Vendor Homepage: [http://phponlinechat.com/phpchat]
# Software Link: [http://phponlinechat.com/chat-free-download.php]
# Version: [3.0]
# Tested on: [win7]
php online chat suffer from xss in user panel
- register as user
- go to : http://path/phpchat/canned_opr.php
- inject javascript evil code into messae filed
demo :
http://phponlinechat.com/phpchat/canned_opr.php
have fun :)