目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-46005 PoC — Sourcecodester Car Rental Management System 跨站脚本漏洞

来源
关联漏洞
标题: Sourcecodester Car Rental Management System 跨站脚本漏洞 (CVE-2021-46005)
Description:Sourcecodester Car Rental Management System是美国Sourcecodester公司的一个汽车租赁管理系统。 Sourcecodester Car Rental Management System 1.0存在安全漏洞,攻击者可通过 vehicalorcview 参数进行跨站脚本 (XSS) 攻击。
Description
CVE-2021-46005
介绍
# CVE-2021-46005
## **All Details about CVE-2021-46005**

Software: Online Car Rental System 1.0

Software Link: https://www.sourcecodester.com/cc/14145/online-car-rental-system-using-phpmysql.html

Vulnerability Type: Stored Cross Site Scripting

Affected Component: vehicalorcview in post-avehical page

Impact Denial of Service: True

Impact Code execution : True

Attack Type: Remote

Vendor of Product: Sourcecodester

## Description:
Cross-site scripting vulnerabilities occur when a parameter under the user’s control is either reflected to the user, stored and returned at a later time, or executed as a result of modifying the DOM environment. The vulnerability exists in Sourcecodester Online Car Rental System 1.0 in vehicalorcview parameter found during Adding new Vehical in Post Vehical page. Simply adding the simple payload <script>alert("CAR")</script> in vehicalcrview parameter, the application store the payload without input validatoin in database and whenever the client visit the page payload executed

The Affected URL where the  vulnerable parameter can be found : http://HOST/car-rental/admin/post-avehical.php

Impact: This vulnerability allows an attacker  to Hijacked session, Steal Credentials, access to client computers installing Malware in client's computer 

## More Info:
https://www.exploit-db.com/exploits/49546
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →