header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Hexamail Server <= 4.4.5 Persistent XSS Vulnerability

Hexamail Server suffers persistent XSS vulnerability in the mail body, allowing malicious user to execute scripts in a victim’s browser to hijack user sessions, redirect users, and or hijack the user’s browser. By sending a malicious script to the victim email, the webmail automatically load the mail body, so the script will be automatically executed without permission from user.

Vanilla Tagging Stored XSS

Vanilla Version 2.0.18.4 is vulnerable to stored XSS. An attacker can create a new thread and post their XSS as a tag. The attacker can bypass the max-length on the form by using a proxy or manipulating the form. Once the thread is posted, an administrator or moderator can be sent to the URL http://server/index.php?p=/vanilla/post/editdiscussion/7, where 7 is the thread ID of the thread just made. The XSS will then trigger. The URL may be different depending on what category the thread is in.

Log1 CMS writeInfo() PHP Code Injection

This module exploits the 'Ajax File and Image Manager' component that can be found in log1 CMS. In function.base.php of this component, the 'data' parameter in writeInfo() allows any malicious user to have direct control of writing data to file data.php, which results in arbitrary remote code execution.

Vanilla Tagging Enchanced 1.0.1 Stored XSS

This plugin is based on the default tagging plugin that comes with Vanilla. Therefore this is vulnerable to the same attack. Create a new thread and post your XSS as tag. Once you have posted the thread, send an administrator or moderator to http://target.tld/index.php?p=/vanilla/post/editdiscussion/7, where 7 is the thread ID of the thread you just made. The XSS will then trigger.

Recent Exploits: