header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Availability Booking Calendar v1.0 – Multiple Cross-site scripting (XSS)

This exploit allows an attacker to inject malicious JavaScript code into the web application, which is then executed by the victim's browser. The exploit is triggered when the user browses to the 'Bookings' page and selects 'All Bookings'. They can then edit a booking and enter a payload in the 'Promo Code' field. The payload in this case is 'TEST"><script>alert(`XSS`)</script>'. When the form is submitted, the payload is stored in the database and later displayed on the 'Bookings' page, resulting in the execution of the malicious script.

Zomplog 3.9 – Cross-site scripting (XSS)

The Zomplog v3.9 application is vulnerable to cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by injecting malicious code into the 'title' parameter of the POST request. This can lead to the execution of arbitrary JavaScript code in the context of the victim's browser.

Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 – Password Dumping

Keeper Security Password vault Desktop application and Browser Extension stores credentials in plain text in memory. This can persist after logout if the user has not explicitly enabled the option to 'clear process memory'. As a result of this one can extract credentials & master password from a victim after achieving low priv access. This does NOT target or extract credentials from the affected browser extension (yet), only the Windows desktop app.

Recent Exploits: