SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
44 stars 0 forks source link

[FullDisclosure] Reflected XSS - fronsetiav1.1 #36155

Open github-actions[bot] opened 8 hours ago

github-actions[bot] commented 8 hours ago

Posted by Andrey Stoykov on Nov 21

# Exploit Title: Reflected XSS - fronsetiav1.1

# Date: 11/2024

# Exploit Author: Andrey Stoykov

# Version: 1.1

# Tested on: Debian 12

# Blog:

https://msecureltd.blogspot.com/2024/11/friday-fun-pentest-series-14-reflected.html

Reflected XSS #1 - "show_operations.jsp"

Steps to Reproduce:

1. Visit main page of the application.

2. In the input field of "WSDL Location" enter the following payload "><img

src=x...

https://seclists.org/fulldisclosure/2024/Nov/10