[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Frog CMS 0.9.5 - Cross-Site Scripting Vulnerability

Author
WangDudu
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-31871
Category
web applications
Date add
02-01-2019
CVE
CVE-2018-20448
Platform
php
# Exploit Title: Frog CMS 0.9.5 - Cross-Site Scripting
# Exploit Author:WangDudu
# Vendor Homepage: https://github.com/philippe/FrogCMS
# Software Link: https://github.com/philippe/FrogCMS
# Version:0.9.5
# CVE :CVE-2018-20448

# The parameter under /install/index.php is that the Database name has reflective XSS
# 1 The Database name , username and password must be correct
# 2 You can use the exp: 

<script>alert(1)</script>

#  0day.today [2024-11-16]  #