PHP Stock Management System 1.02 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Author: Ragha Deepthi K R
type: webapps
platform: php
port:
date_added: 2014-09-08
date_updated: 2014-09-08
verified: 1
codes: OSVDB-111555;OSVDB-111554
tags:
aliases:
screenshot_url: http://www.exploit-db.com/screenshots/idlt34500/screen-shot-2014-09-08-at-102138.png
application_url:
# Exploit Title: Multiple Persistent Cross Site Scripting Vulnerabilities
in PHP Stock Management System 1.02
# Date: 25 Aug 2014
# Exploit Author: Ragha Deepthi K R
# Vendor Homepage: http://www.posnic.com/
# Software Link: http://sourceforge.net/projects/stockmanagement/
# Version: 1.02
# Tested on: Windows 7
#################################################
PHP Stock Management System 1.02 is vulnerable for multiple Persistent
Cross Site Scripting Vulnerabilities.
The vulnerability affects 'sname'(Store Name Field), 'address'(Address
Field), 'place'(Place Field), 'city'(City Field), pin(Pin Field),
website(Website Field), email(Email Field) parameters while updating the
store details in 'update_details.php' and when seen in 'view_report.php'
#################################################
Greetz : Syam !