what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Seat Reservation System 1.0 Cross Site Scripting

Seat Reservation System 1.0 Cross Site Scripting
Posted Oct 8, 2020
Authored by George Tsimpidas

Seat Reservation System version 1.0 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 5c72dbedbfc6f5c6f4311358863d0d77b22e14b47aed804311019b7b2b6de3af

Seat Reservation System 1.0 Cross Site Scripting

Change Mirror Download
# Exploit Title: Seat Reservation System 1.0 Persistent Cross-Site Scripting
# Date: 10-08-2020
# Exploit Author: George Tsimpidas
# Vendor Homepage: www.sourcecodester.com
# Software Link:
https://www.sourcecodester.com/sites/default/files/download/oretnom23/seat-reservation-system-using-php_0.zip
# Version: 1.0
# Tested on: Ubuntu 18.04.5 LTS (Bionic Beaver)
# Category: Webapp

Description :

The file movie_list.php does not sanitize correctly the description
drop down menu on the edit mode,
therefore it echoes out the data on the parsed ID number of the
current indicated movie.

Culprit :

#########################################################################
<div class="dropdown-menu">
<a class="dropdown-item edit_movie" href="javascript:void(0)" data-id
= '<?php echo $row['id'] ?>'>Edit</a>

#########################################################################


PoC :

1. Navigate on the admin panel and login :
http://localhost/seat_reservation/admin/

2. Go under the category Movie List

3. Click on Edit, and change the description of the Movie "The Matrix"

4. Apply on the description the below payload : <script>alert("XSS")</script>

5. Click save, and visit the main menu : http://localhost/seat_reservation/

6. Locate the movie " The Matrix " and click Reserve Seat

You will be granted with a Cross Site Scripting Alert.
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    0 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close