CVE-2022-46888: NexusPHP <1.7.33 - Cross-Site Scripting

CVE-2022-46888: NexusPHP <1.7.33 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2022-46888: NexusPHP <1.7.33 - Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-46888: NexusPHP <1.7.33 – Cross-Site Scripting

漏洞描述

NexusPHP before 1.7.33 contains multiple cross-site scripting vulnerabilities via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php. An attacker can inject arbitrary web script or HTML, which can allow theft of cookie-based authentication credentials and launch of other attacks..

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享