Menu

Search for hundreds of thousands of exploits

"Match Clone Script 1.0.4 - Cross-Site Scripting"

Author

Exploit author

ManhNho

Platform

Exploit platform

php

Release date

Exploit published date

2018-04-18

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
########################################################################
# Exploit Title: Match Clone Script 1.0.4 - Cross-Site Scripting
# Date: 23.02.2018
# Vendor Homepage: https://www.phpscriptsmall.com/
# Software Link: https://www.phpscriptsmall.com/product/match-clone/
# Category: Web Application
# Exploit Author: ManhNho
# Version: 1.0.4
# Tested on: Window 10 / Kali Linux
# CVE: CVE-2018-9857
##########################################################################
Description
------------------------
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to
searchbyid.php (aka the "View Search By Id" screen).

Proof of Concept
------------------------
1. Access to site
2. Choose Search
3. Choose "View Search By Id"
3. Put <script>alert('ManhNho')</script> in search field
4. You will be having a popup: ManhNho

References:
------------------------
https://pastebin.com/Y9uEC4nu
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9857
Release Date Title Type Platform Author
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2019-05-28 "EquityPandit 1.0 - Password Disclosure" local android ManhNho
2019-03-08 "DirectAdmin 1.55 - 'CMD_ACCOUNT_ADMIN' Cross-Site Request Forgery" webapps php ManhNho
2018-08-20 "WordPress Plugin Tagregator 0.6 - Cross-Site Scripting" webapps php ManhNho
2018-06-20 "MaDDash 2.0.2 - Directory Listing" webapps java ManhNho
2018-06-07 "Ftp Server 1.32 - Credential Disclosure" local android ManhNho
2018-05-27 "Werewolf Online 0.8.8 - Information Disclosure" local android ManhNho
2018-04-18 "Match Clone Script 1.0.4 - Cross-Site Scripting" webapps php ManhNho
2018-04-10 "WordPress Plugin File Upload 4.3.3 - Stored Cross-Site Scripting (PoC)" webapps php ManhNho
2018-04-10 "WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting" webapps php ManhNho
2018-04-10 "iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting" webapps php ManhNho
2018-04-09 "iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC)" webapps php ManhNho
2018-04-09 "Yahei PHP Prober 0.4.7 - Cross-Site Scripting" webapps php ManhNho
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.