exploit-db-mirror/platforms/php/webapps/37144.txt
Offensive Security 0b3f393d50 DB: 2015-05-30
17 new exploits
2015-05-30 05:02:42 +00:00

9 lines
No EOL
583 B
Text
Executable file

source: http://www.securityfocus.com/bid/53433/info
OrangeHRM is prone to an SQL-injection and multiple cross-site scripting vulnerabilities.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OrangeHRM 2.7 RC is vulnerable; prior versions may also be affected.
http://www.example.com/templates/hrfunct/emppop.php?reqcode=1&sortOrder1=%22%3E%3Cscript%3Ealert%28docume nt.cookie%29;%3C/script%3E