欢迎光临
我们一直在努力

4images 跨站脚本漏洞

|漏洞来源
https://cxsecurity.com/issue/WLB-2021070071
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202103-1272
|漏洞详情
Piyush Patil 4images是 (Piyush Patil)开源的一个应用系统。一个图片管理系统。 4images version 1.8 存在跨站脚本漏洞,该漏洞允许远程攻击者可利用该漏洞通过“重定向”参数注入JavaScript。
|漏洞EXP
[loginshow]
# Exploit Title: 4Images 1.8 - 'redirect' Reflected XSS
# Exploit Author: Piyush Patil
# Vendor Homepage: https://www.4homepages.de/
# Software Link: https://www.4homepages.de/?download=4images1.8.zip&code=81da0c7b5208e172ea83d879634f51d6
# Version: 4Images Gallery 1.8
# Tested on: Windows 10 and Kali
# CVE : CVE-2021-27308

-Description:
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.


-Steps to reproduce:
1- Goto 4images admin panel page (demo instance: https://localhost/4images/admin/index.php)
2- Enter the credentials , Turn on the intercept and click on "Login"
3- copy paste the XSS payload after redirect=./../admin/index.php%3Fsessionid=xxxxxPASTEPAYLOADHERE
4-Forward the request and you can see XSS is triggered.
[/loginshow]
赞(0) 打赏
未经允许不得转载:黑客技术网 » 4images 跨站脚本漏洞
分享到: 更多 (0)

评论 抢沙发

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址

觉得文章有用就打赏一下文章作者

支付宝扫一扫打赏

微信扫一扫打赏