Open in app

Sign In

Write

Sign In

GrimTheRipper
GrimTheRipper

21 Followers

Home

About

Oct 31, 2022

[CVE-2022–42098]KLiK SQL INJECTION

KLiK-SocialMediaWebsite version v1.0.1 Vulnerability Explanation: KLiK-SocialMediaWebsite v1.0.1 has SQL Injection Vulnerabilities on profile.php at parameter id. Attack Vectors: KLiK-SocialMediaWebsite v1.0.1 Once an user has been created it can also be find people on KLiK through the KLiK Users page. The “id” parameter of the profile.php can be abused for injecting arbitrary SQL queries. Affected:

1 min read

1 min read


Oct 31, 2022

[CVE-2022–42097]Backdrop-XSS-at-Comments

Enter your username and password; the account must have admin privileges. Select some post at the main website.

2 min read

[CVE-2022–42097]Backdrop-XSS-at-Comments
[CVE-2022–42097]Backdrop-XSS-at-Comments

2 min read


Oct 31, 2022

[CVE-2022–42096]Backdrop-XSS-at-Posts

Enter your username and password; the account must have admin privileges. Select Content > add content > Post

2 min read

[CVE-2022–42096]Backdrop-XSS-at-Posts
[CVE-2022–42096]Backdrop-XSS-at-Posts

2 min read


Oct 31, 2022

[CVE-2022–42095][Declined]Backdrop-XSS-at-Pages

Enter your username and password; the account must have admin privileges. Select Content > add content > Page

2 min read

[CVE-2022–42095][Declined]Backdrop-XSS-at-Pages
[CVE-2022–42095][Declined]Backdrop-XSS-at-Pages

2 min read


Oct 31, 2022

[CVE-2022–42094]Backdrop-XSS-at-Cards

Enter your username and password; the account must have admin privileges. Select Content > add content > Card

2 min read

[CVE-2022–42094]Backdrop-XSS-at-Cards
[CVE-2022–42094]Backdrop-XSS-at-Cards

2 min read


Sep 30, 2022

Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Description

Vulnerability Explanation: Piwigo Version 12.3.0 has XSS vulnerabilities that allow attackers to store XSS via Photo Description input. Affected Component: http://[IP]/admin.php?page=photos-5 Payload: <image src/onerror=console.log("test_xss_at_Description")> Tested on: Piwigo Version 12.3.0 https://piwigo.org/get-piwigoa Brave Version 1.44.101 Chromium: 106.0.5249.65 (Official Build) (64-bit) Steps to attack:

Xss Attack

2 min read

Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Description
Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Description
Xss Attack

2 min read


Sep 30, 2022

Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Author

Vulnerability Explanation: Piwigo Version 12.3.0 has XSS vulnerabilities that allow attackers to store XSS via Photo Author input. Affected Component: http://[IP]/admin.php?page=photos-4 Payload: <image src/onerror=console.log("test_xss_at_Author")> Tested on: Piwigo Version 12.3.0 https://piwigo.org/get-piwigoa Brave Version 1.44.101 Chromium: 106.0.5249.65 (Official Build) (64-bit) Steps to attack:

Xss Attack

2 min read

Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Author
Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Author
Xss Attack

2 min read


Sep 30, 2022

Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Title

Vulnerability Explanation: Piwigo Version 12.3.0 has XSS vulnerabilities that allow attackers to store XSS via Photo Title input. Affected Component: http://[IP]/admin.php?page=photos-3 Payload: <image src/onerror=console.log("test_xss_at_Photo_Title")> Tested on: Piwigo Version 12.3.0 https://piwigo.org/get-piwigoa Brave Version 1.44.101 Chromium: 106.0.5249.65 (Official Build) (64-bit) Steps to attack:

Xss Attack

3 min read

Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Title
Piwigo 12.3.0 — Stored XSS Vulnerability at Photo Title
Xss Attack

3 min read


Sep 30, 2022

Piwigo 12.3.0 — Stored XSS Vulnerability at Tags

Vulnerability Explanation: Piwigo Version 12.3.0 has XSS vulnerabilities that allow attackers to store XSS via tag input. Affected Component: http://[IP]/admin.php?page=tags Payload: <image src/onerror=console.log("test_xss_at_Tags")> Tested on: Piwigo Version 12.3.0 https://piwigo.org/get-piwigoa Brave Version 1.44.101 Chromium: 106.0.5249.65 (Official Build) (64-bit) Steps to attack: 1. First, we log in with an admin credential to the target application.

Xss Attack

2 min read

Piwigo 12.3.0 — Stored XSS Vulnerability at Tags
Piwigo 12.3.0 — Stored XSS Vulnerability at Tags
Xss Attack

2 min read


Sep 30, 2022

Piwigo 12.3.0 — Stored XSS Vulnerability at Gallery title

Vulnerability Explanation: Piwigo Version 12.3.0 has XSS vulnerabilities that allow attackers to store XSS via Gallery title input. Affected Component: http://[IP]/admin.php?page=configuration Payload: <image src/onerror=console.log("test_xss_at_Gallery_title")> Tested on: Piwigo Version 12.3.0 https://piwigo.org/get-piwigoa Brave Version 1.44.101 Chromium: 106.0.5249.65 (Official Build) (64-bit) Steps to attack:

Xss Attack

2 min read

Piwigo 12.3.0 — Stored XSS Vulnerability at Gallery title
Piwigo 12.3.0 — Stored XSS Vulnerability at Gallery title
Xss Attack

2 min read

GrimTheRipper

GrimTheRipper

21 Followers

You get the best out of others when you give the best of yourself

Following
  • Musyoka Ian

    Musyoka Ian

  • Pichaya Morimoto

    Pichaya Morimoto

  • PlyNatwara

    PlyNatwara

  • PentesterLab

    PentesterLab

  • George O

    George O

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech