このウェブページからのスクリーンショットから、以下の脆弱性情報を得ることができます: 1. 脆弱性タイトル:SourceCodester Clinics Patient Management System 2.0 Cross Site Scripting 2. 対象プロジェクト:https://www.sourcecodester.com/php/17556/contact-manager-export-vcf-using-php-and-mysql-source-code.html 3. 対象バージョン:2.0 4. 関連コード:/users.php 行番号: 256-259 5. パラメータ:/users.php?message=hello 6. POC(Proof of Concept)手順: - Clinics Patient Management System - PHP 2.0 をダウンロードして設定する - アカウントにログインし、「/users.php?message=hello」にアクセスする - message パラメータの値を XSS ペイロードに置き換える - 反射型 XSS を観察する - リンクを直接クリックしてログインする(詳細は推奨リンクを参照) - http://192.168.95.115/users.php?message=> 7. 出典:https://github.com/gurudattch/CVEs/blob/main/Sourcecodester-Clinic's-Patient-Management-System-Reflected-XSS.md 8. 報告者:guru (ID 74056) 9. 報告日時:2024年4月9日 12:07 PM (3日前) 10. 審査日時:2024年6月9日 11:22 PM (2日後) 11. ステータス:Accepted 12. VulDB エントリ:276773 これらの情報は、脆弱性の性質、影響範囲、攻撃手法、および報告プロセスを詳細に説明しています。