[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Flippy My Life Stories 2.0 XSS Vulnerability

Author
Conslight
Risk
[
Security Risk High
]
0day-ID
0day-ID-23917
Category
web applications
Date add
22-07-2015
Platform
php
_________                              .__    .__     ____   .__        __   
\_   ___ \    ____     ____     ______ |  |   |__|   / ___\  |  |__   _/  |_ 
/   \  \/   /  _ \   /    \   /  ___/ |  |    |  |  / /_/  > |  |  \  \   __\
\    \____ (  <_> ) |   |  \  \___ \  |  |__  |  |  \___  /  |   Y  \  |  |  
 \_______/  \____/  |___|__/ /______> |____/  |__|  /____/   |___|__/  |__|  
                                                                                   

Cross-Site Scripting in Flippy My Life Stories 2.0

Information 
-------------------- 

# Exploit Title: Cross-Site Scripting in Flippy My Life Stories 2.0
# Date: 22/07/2015
# Author: Conslight
# Vendor Homepage: http://www.flippyscripts.com/
# Version: 2.0
# Tested on: Debian & Windows 7
# Type : Stored XSS

Description 
-------------------- 
Stored XSS is available on register system. Anyone can put Javascript code in register panel, then the code will be activate in user information panel.

Details 
-------------------- 
Everything is explained on the video.

1: Go to http://website.fr/register.html
2: In "nickname" type Javascript code like <script>alert(2)</script>
3: Go to http://website.fr/userlogin.html and Log in
4: Click on "My Stories", it will lead you on the vulnerable page.
	 
Vidéo 
-------------------- 
https://youtu.be/gPutq4uCXSQ

#  0day.today [2024-11-16]  #