Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-46974 PoC — Best Courier Management System 跨站脚本漏洞

Source
Associated Vulnerability
Title:Best Courier Management System 跨站脚本漏洞 (CVE-2023-46974)
Description:Best Courier Management System是Mayuri K.个人开发者的一个快递管理系统。 Best Courier Management System v.1.000版本存在跨站脚本漏洞,该漏洞源于允许远程攻击者通过 URL 中的page 参数使用精心设计的负载执行任意代码。
Description
POC
Readme
# CVE-2023-46974
POC

> [Description]
> Cross Site Scripting vulnerability in Best Courier Management System
> v.1.000 allows a remote attacker to execute arbitrary code via a
> crafted payload to the page parameter in the URL.
>
> ------------------------------------------
>
> [Vulnerability Type]
> Cross Site Scripting (XSS)
>
> ------------------------------------------
>
> [Vendor of Product]
> https://www.sourcecodester.com/php/16848/best-courier-management-system-project-php.html
>
> ------------------------------------------
>
> [Affected Product Code Base]
> v 1.000 - Best courier management system
>
> ------------------------------------------
>
> [Affected Component]
> All URL's
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> exploitation possible via link (Remote)
>
> ------------------------------------------
>
> [Reference]
> https://youtu.be/5oVfJHT_-Ys
>
> ------------------------------------------
>
> [Discoverer]
> Yagyesh K. Tiwari
File Snapshot

[4.0K] /data/pocs/65f1fe9804e48cbe3c3ccb01f54218c1ec02e4aa └── [1.1K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.