Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Exploit Collector
WordPress GiveWP 2.9.7 Cross Site Scripting

https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
WordPress GiveWP plugin version 2.9.7 suffers from a cross site scripting vulnerability.

MD5 | e1d2d3f9920ae4f2a8d888e6f91a3b5e

Download
# Exploit Title: GiveWP 2.9.7 Reflected Cross-Site Scripting
# Date: 3/23/2021
# Exploit Author: Austin Bentley
# Vendor Homepage: https://givewp.com/
# Software Link: https://wordpress.org/plugins/give/
# Version: 2.9.7
# Tested on: Windows 7
# CVE: CVE-2021-24213
Exploitation requirements: Admin must visit payload URL. Default config.
Tested on: GiveWP 2.9.7, Wordpress 5.7, XAMPP 7.4.16, Firefox 86.0.1. Default configs on all products.
Vulnerable since: 2.4.0, Jan 16th 2019, commit 097c4d0ab964493776950381ed64498040395f6b
Active Installations: 100,000+ per https://wordpress.org/plugins/give/
Researcher: Austin Bentley (https://bentl.ee/)
Detailed writeup available at httpS://bentl.ee/posts/cve-givewp/

PoC URL:
http://localhost/wp-admin/edit.php?s=%22%3E&start-date&end-date&form_id=0&action=-1&paged=1&give_action=delete_bulk_donor&orderby=id&order=DESC&action2=-1&post_type=give_forms&page=give-donors&view=donors

Response:
--- SNIP ---
">
--- SNIP ---
Disclosure Log:
3/21/2021 -- Emailed GiveWP for security contact information
3/22/2021 -- WPScan CNA issued CVE-2021-24213 (un-released)
3/22/2021 -- Provided vendor with PoC
3/22/2021 -- Vendor provided fix in 2.10.0
3/23/2021 -- Fix validated, article posted, CVE unlocked

Source:packetstormsecurity.com
Exploit Collector
Hotel And Lodge Management System 1.0 Cross Site Scripting

https://4.bp.blogspot.com/-INMz00VTlDg/WWlvPzJvf6I/AAAAAAAAIM4/tZDwU9OuM_wuiTGIuyom6E8lddjUI2D5ACLcBGAs/s1600/h29.png
Hotel And Lodge Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

MD5 | 12607984bffdb3f965f7fdd61ed0ae52

Download
# Exploit Title: Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS
# Exploit Author: Jitendra Kumar Tripathi
# Vendor Homepage: https://www.sourcecodester.com/php/13707/hotel-and-lodge-management-system.html
# Software Link: https://www.sourcecodester.com/download-code?nid=13707&title=Hotel+and+Lodge+Management+System+using+PHP+with+Source+Code
# Version: 1
# Tested on Windows 10 + Xampp 8.0.3

XSS IMPACT:
1: Steal the cookie
2: User redirection to a malicious website

Vulnerable Parameters: Customer Details

*Steps to reproduce:*
1: Log in with a valid username and password. Navigate to the Customer Details (http://localhost/hotel/source%20code/index.php) on the left-hand side.
2: Add the new customer and then add the payload in Customer Name parameter and click on save button. Post Saved successfully.
3: Now, XSS will get stored and trigger every time when you click view customer and the attacker can steal authenticated users' cookies.


Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Taking the eJPT This Week

This is the the week, well more specifically Thursday, I got my voucher for the eLearnSecurity eJPT yesterday and today I’ve written…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
fd challange walkthough

in this series i will solve a simple walktough of fd challenge available on

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Automate WordPress recon for Bug Bounty | WordPress:Cheat sheet

https://cdn-images-1.medium.com/max/750/1*bWMFqIUwiUYzz3ScpthkYw.jpeg
WordPress is a fairly large and complex product, with its own pros and cons, so there are a sufficient number of tools that allow you to…

Continue reading on Medium »
During our product phase, Apron offered a Bug Bounty reward to the developers reviewing Apron node on Dashboard and reporting bugs.Continue reading on Medium » (https://apron-network.medium.com/reward-announcement-of-bug-bounty-program-4881433c3f43?source=rss------bug_bounty-5)
I have nothing for me but want to make a change
https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/

<!-- SC_OFF -->I'm a student currently going for a major in cybersecurity. I have been thinking about my future and I have nothing going on for me. I'm not involved in any clubs, I barely know the bare minimum for coding, I have done nothing to put in my resume for a future job, Once I do finish college, I will have nothing that makes me stand out to companies other than a degree. I'm asking for some guidance here, what should I do. I enjoy the idea of ethical "hacking" but have no knowledge of where to start and how I could use this knowledge for a possible internship in the future. I just don't want to be another student with a degree but yet I'm working retail <!-- SC_ON --> submitted by /u/hirosama555 (https://www.reddit.com/user/hirosama555)
[link] (https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbmaqd/i_have_nothing_for_me_but_want_to_make_a_change/)