{"id":45403,"date":"2023-07-21T19:03:43","date_gmt":"2023-07-21T15:03:43","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173675\/cmsbmpm100-xss.txt"},"modified":"2023-07-22T10:46:12","modified_gmt":"2023-07-22T06:16:12","slug":"cms-bank-mellat-payment-manager-1-0-0-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cms-bank-mellat-payment-manager-1-0-0-cross-site-scripting\/","title":{"rendered":"CMS-Bank Mellat Payment Manager 1.0.0 Cross Site Scripting"},"content":{"rendered":"<p>====================================================================================================================================<br \/>\n| # Title : CMS-Bank Mellat Payment Manager v1.0.0 Xss Vulnerability |<br \/>\n| # Author : indoushka |<br \/>\n| # Tested on : windows 10 Fran\u00e7ais V.(Pro) \/ browser : Mozilla firefox 114.0.2 (64 bits) |<br \/>\n| # Vendor : https:\/\/github.com\/ |<br \/>\n| # Dork : |<br \/>\n====================================================================================================================================<\/p>\n<p>poc :<\/p>\n[+] Dorking \u0130n Google Or Other Search Enggine.<\/p>\n[+] Cross site scripting (also referred to as XSS) is a vulnerability that allows an attacker to send malicious code<br \/>\n(usually in the form of Javascript) to another user.<br \/>\nBecause a browser cannot know if the script should be trusted or not, it will execute the script in the user context<br \/>\nallowing the attacker to access any cookies or session tokens retained by the browser.<\/p>\n[+] Affected items :<\/p>\n<p>\/bank\/default.php<br \/>\n\/bank\/index.php<\/p>\n[+] The impact of this vulnerability :<\/p>\n<p>Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data<br \/>\nfrom them. An attacker can steal the session cookie and take over the account, impersonating the user. It is also possible to modify<br \/>\nthe content of the page presented to the user.<\/p>\n[+] How to fix this vulnerability :<\/p>\n<p>Your script should filter metacharacters from user input.<br \/>\nCross site scripting (also referred to as XSS) is a vulnerability that allows an attacker to send malicious code<br \/>\n(usually in the form of Javascript) to another user. Because a browser cannot know if the script should be trusted or not,<br \/>\nit will execute the script in the user context allowing the attacker to access any cookies or session tokens retained by the browser.<\/p>\n[+] Attack details :<\/p>\n<p>URL encoded POST input PayAdditionalData was set to 01\/01\/1967&#8243; onmouseover=prompt(940051) bad=&#8221;<br \/>\nThe input is reflected inside a tag parameter between double quotes.<\/p>\n<p>URL encoded POST input PayAmount was set to 1&#8243; onmouseover=prompt(911818) bad=&#8221;<br \/>\nThe input is reflected inside a tag parameter between double quotes.<\/p>\n<p>URL encoded POST input pay_from was set to 1&#8243; onmouseover=prompt(965239) bad=&#8221;<br \/>\nThe input is reflected inside a tag parameter between double quotes.<\/p>\n<p>URL encoded POST input pay_from1 was set to 1&#8243; onmouseover=prompt(951829) bad=&#8221;<br \/>\nThe input is reflected inside a tag parameter between double quotes.<\/p>\n<p>Greetings to :=========================================================================================================================<br \/>\njericho * Larry W. Cashdollar * brutelogic* shadow_00715* 9aylas * djroot.dz * LiquidWorm* Hussin-X *D4NB4R * ViRuS_Ra3cH * yasMouh |<br \/>\n=======================================================================================================================================<\/p>\n","protected":false},"excerpt":{"rendered":"<p>==================================================================================================================================== | # Title : CMS-Bank Mellat Payment Manager v1.0.0 Xss Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Fran\u00e7ais V.(Pro) \/ browser : Mozilla firefox 114.0.2 (64 bits) | | # Vendor : https:\/\/github.com\/ | | # Dork : | ==================================================================================================================================== poc : [+] Dorking \u0130n Google &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45403","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45403"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45403\/revisions"}],"predecessor-version":[{"id":45439,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45403\/revisions\/45439"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}