Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- htmly 2.9.9 Cross Site Scripting[6]
- Authored by Andrey Stoykov[7] | Site msecureltd.blogspot.com[8]
-
htmly version 2.9.9 suffers from multiple persistent cross site scripting vulnerabilities.
- SHA-256 |
b19a6a9192ab7fdb974bbaace4e6310aa155520d7f2a2c087e43a0e209b862b0 - Download[9] | Favorite[10] | View[11]
Change Mirror[12] Download[13]
# Exploit Title: Stored XSS in "Edit Profile" - htmlyv2.9.9
# Date: 9/2024
# Exploit Author: Andrey Stoykov
# Version: 2.9.9
# Tested on: Ubuntu 22.04
# Blog:
https://msecureltd.blogspot.com/2024/09/friday-fun-pentest-series-11-stored-xss.html
Stored XSS #1:
Steps to Reproduce:
1. Login as author
2. Browse to "Edit Profile"
3. In "Content" field add payload "><img src=x onerror=alert(1)>
4. Then refresh the "Edit Profile" page
# Exploit Title: Stored XSS in "Menu Editor" - htmlyv2.9.9
# Date: 9/2024
# Exploit Author: Andrey Stoykov
# Version: 2.9.9
# Tested on: Ubuntu 22.04
# Blog:
https://msecureltd.blogspot.com/2024/09/friday-fun-pentest-series-10-stored-xss.html
Stored XSS #1:
Steps to Reproduce:
1. Login as admin
2. Browse to "Menu Editor"
3. In "Name" field add payload "><img src=x onerror=alert(1)>
4. In "Slug" field add payload "><img src=x onerror=alert(1)>
5. Click "Save Edit" > "Save Menu"
File Tags
- ActiveX[19] (933)
- Advisory[20] (86,834)
- Arbitrary[21] (17,072)
- BBS[22] (2,859)
- Bypass[23] (1,923)
- CGI[24] (1,047)
- Code Execution[25] (7,900)
- Conference[26] (692)
- Cracker[27] (845)
- CSRF[28] (3,426)
- DoS[29] (25,259)
- Encryption[30] (2,394)
- Exploit[31] (54,258)
- File Inclusion[32] (4,273)
- File Upload[33] (1,016)
- Firewall[34] (822)
- Info Disclosure[35] (2,915)
- Intrusion Detection[36] (918)
- Java[37] (3,156)
- JavaScript[38] (908)
- Kernel[39] (7,281)
- Local[40] (14,850)
- Magazine[41] (587)
- Overflow[42] (13,221)
- Perl[43] (1,435)
- PHP[44] (5,270)
- Proof of Concept[45] (2,411)
- Protocol[46] (3,749)
- Python[47] (1,658)
- Remote[48] (31,884)
- Root[49] (3,671)
- Rootkit[50] (529)
- Ruby[51] (642)
- Scanner[52] (1,658)
- Security Tool[53] (8,047)
- Shell[54] (3,305)
- Shellcode[55] (1,219)
- Sniffer[56] (904)
- Spoof[57] (2,297)
- SQL Injection[58] (16,724)
- TCP[59] (2,463)
- Trojan[60] (690)
- UDP[61] (919)
- Virus[62] (675)
- Vulnerability[63] (33,087)
- Web[64] (10,138)
- Whitepaper[65] (3,784)
- x86[66] (970)
- XSS[67] (18,300)
- Other[68]
File Archives
- September 2024[69]
- August 2024[70]
- July 2024[71]
- June 2024[72]
- May 2024[73]
- April 2024[74]
- March 2024[75]
- February 2024[76]
- January 2024[77]
- December 2023[78]
- November 2023[79]
- October 2023[80]
- Older[81]
Systems
- AIX[82] (430)
- Apple[83] (2,114)
- BSD[84] (378)
- CentOS[85] (61)
- Cisco[86] (1,954)
- Debian[87] (7,123)
- Fedora[88] (1,693)
- FreeBSD[89] (1,247)
- Gentoo[90] (4,567)
- HPUX[91] (881)
- iOS[92] (389)
- iPhone[93] (108)
- IRIX[94] (220)
- Juniper[95] (71)
- Linux[96] (51,208)
- Mac OS X[97] (696)
- Mandriva[98] (3,105)
- NetBSD[99] (256)
- OpenBSD[100] (489)
- RedHat[101] (16,823)
- Slackware[102] (941)
- Solaris[103] (1,615)
- SUSE[104] (1,444)
- Ubuntu[105] (9,847)
- UNIX[106] (9,455)
- UnixWare[107] (188)
- Windows[108] (6,772)
- Other[109]
- Services
- Security Services[120]
- Hosting By
- Rokasec[121]


