[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PhpOnlineChat 3.0 - XSS Vulnerability

Author
N0 Feel
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-22608
Category
web applications
Date add
08-09-2014
Platform
php
# Exploit Title: [phponlinechat xss ]
# Date: [5/9/2014]
# Exploit Author: [N0 Feel]
# Vendor Homepage: [http://phponlinechat.com/phpchat]
# Software Link: [http://phponlinechat.com/chat-free-download.php]
# Version: [3.0]
# Tested on: [win7]
 
php online chat suffer from xss in user panel
 
- register as user
- go to : http://path/phpchat/canned_opr.php
- inject javascript evil code into messae filed
 
demo  :
http://phponlinechat.com/phpchat/canned_opr.php
 
have fun :)

#  0day.today [2024-11-15]  #