Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-18024 PoC — AvantFAX 跨站脚本漏洞

Source
Associated Vulnerability
Title:AvantFAX 跨站脚本漏洞 (CVE-2017-18024)
Description:AvantFAX是一套用于查看和发送传真的软件。该软件支持用户管理、权限管理、传真线路管理和传真类别管理等。 AvantFAX 3.3.3版本中存在跨站脚本漏洞。远程攻击者可通过向默认URI注入任意的参数名利用该漏洞注入任意的Web脚本或HTML。
Description
AvantFAX 3.3.3 contains a cross-site scripting vulnerability via an arbitrary parameter name submitted to the default URL, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
File Snapshot

id: CVE-2017-18024 info: name: AvantFAX 3.3.3 - Cross-Site Scripting author: pikpikcu severit ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.