Datoo Complete Dating Script version 1.0 suffers from an html injection vulnerability.
6ff697689f7bbcad80da1988a407104f2abbe6fedf40761d39996b8f78276efc
====================================================================================================================================
| # Title : Datoo - Complete Dating Script v1.0 HTML Inject Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 64.0.2 (32-bit) |
| # Vendor : https://www.codelist.cc/scripts/232821-datoo-v10-complete-dating-script.html |
====================================================================================================================================
poc :
[+] Dorking İn Google Or Other Search Enggine .
[+] create a new use and after login go messages and paste html code .
[+] use payload :
</tr>
<td align="center"><a href="https://packetstormsecurity.com/files/authors/7697"><img src="https://packetstatic.com/img1398360120/ps_logo.png" alt="" width="650" height="120" border="0" /></a>
</tr>
Greetings to :=========================================================================================================================
jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr |
=======================================================================================================================================