目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2020-25271 PoC — PHP 跨站脚本漏洞

来源
关联漏洞
标题: PHP 跨站脚本漏洞 (CVE-2020-25271)
Description:PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHPGroup和开放源代码社区的共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHPGurukul hospital-management-system-in-php 4.0版本存在跨站脚本漏洞,该漏洞源于admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointme
介绍
# CVE-2020-25271

# PHPGurukul hospital-management-system-in-php 4.0 allows XSS via
> admin/patient-search.php,

> doctor/search.php,

> book-appointment.php,

> doctor/appointment-history.php, or

> admin/appointment-history.php.


#Vendor - PHPGurukul

#Product -https://phpgurukul.com/hospital-management-system-in-php  V 4.0

#Vulnerability Type - Cross Site Scripting (XSS)

#Addition Information - Single XSS payload will trigger in all Dashboard, so account take over will be occurred.

#Affected Component - Books > New Book ,[ http:///lms/index.php?page=books] http:///lms/index.php?page=books

#Attack Type- Local

#Privilege Escalation - true

#Impact Code execution - true

> ***Attack Vector***
> --------------------
>
>
> Cross site scripting in  Admin | View Patients (http://localhost/hospital/hms/admin/patient-search.php)
>
>
> Stored XSS in User | Dashboard ( Name field)
>
>
> Cross site scripting in  Doctor | Manage Patients (http://localhost/hospital/hms/doctor/search.php)
>
>
> Install Hospital Management System V 4.0
>
>
>***1) Patient Module***
> ________________
>
>  i.  Create patient account account with username "<script>alert(`XSS`);</script>" , XSS will be triggered in every page of Patient Dashboard
> 
>  ii. Make an appointment  at "Book Appointment" (http://localhost/hospital/hms/book-appointment.php).
>
>
>
> ***2) Doctor Module***
> ________________
>
>  i. Login as doctor who was requested appointment by malicious patient
> 
>  ii. Go to "Appointment History" (http://localhost/hospital/hms/doctor/appointment-history.php), XSS will trigger also.
> 
> 
>
> ***3) Admin Module***
>
>  i.  Login as admin
>  ii. Go to "Appointment History" (http://localhost/hospital/hms/admin/appointment-history.php), XSS will trigger.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →