• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

xss

  1. 1

    Exploits WiKID Systems 2FA Enterprise Server 4.2.0-b2032 SQL Injection / XSS / CSRF

    WiKID Systems 2FA Enterprise Server version 4.2.0-b2032 suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities. View the full article
  2. itsMe

    Traxss - Automated XSS Vulnerability Scanner

    Automated Vulnerability Scanner for XSS | Written in Python3 | Utilizes Selenium Headless Traxss is a Hacktoberfest Project! If you are looking for a place to make contribute, please feel free. Traxss is an automated framework to scan URLs and webpages for XSS Vulnerabilities. It includes over...
  3. 1

    Exploits ASUS RT-N10+ 2.0.3.4 CSRF / XSS / Command Execution

    ASUS RT-N10+ with firmware version 2.0.3.4 suffers from cross site request forgery and cross site scripting vulnerabilities that can assist with achieving command execution. View the full article
  4. 1

    Exploits Open-Xchange OX App Suite SSRF / XSS / Information Disclosure / Access Controls

    Various Open-Xchange OX App Suite versions suffer from server-side request forgery, cross site scripting, information disclosure, and improper access control vulnerabilities. View the full article
  5. 0x1

    Tools Traxss

    Automated Vulnerability Scanner for XSS | Written in Python3 | Utilizes Selenium Headless Traxss is a Hacktoberfest Project! If you are looking for a place to make contribute, please feel free. Traxss is an automated framework to scan URLs and webpages for XSS Vulnerabilities. It includes...
  6. 1

    Exploits Thailand Union Library Management 6.2 SQL Injection / XSS

    Thailand Union Library Management version 6.2 suffers from cross site scripting and remote SQL injection vulnerabilities. View the full article
  7. dEEpEst

    finefriends.social Stored XSS PoC (rewaded HoF)

    Hidden content
  8. 0x1

    Block Alert XSS

    Blocked Window Alert - Prompt - Confirm - Open XSS && block function Window.Console To deblock make var DEBUG = true   if i have forget some function you can add here on Comment Thanks Hidden content Tested on my Blog: Hidden content Reference : Hidden content
  9. 0x1

    vBulletin Reflected XSS

    Hidden content
  10. itsMe

    XSpear - Powerfull XSS Scanning And Parameter Analysis Tool

    XSpear - Powerfull XSS Scanning And Parameter Analysis Tool Key features Pattern matching based XSS scanning     Detect alert confirm prompt event on headless browser (with Selenium)     Testing request/response for XSS protection bypass and reflected params     Reflected Params...
  11. 1

    Exploits D-Link 6600-AP XSS / DoS / Information Disclosure

    D-Link 6600-AP suffers from cross site scripting, key extraction, shell escape, config file disclosure, and denial of service vulnerabilities. View the full article
  12. dEEpEst

    [Python] Exploit XSS with an Image

    Hidden content
  13. itsMe

    XSS Fuzzer: generates XSS payloads based on user-defined vectors and fuzzing lists

    XSS Fuzzer is a simple application written in plain HTML/JavaScript/CSS which generates XSS payloads based on user-defined vectors using multiple placeholders which are replaced with fuzzing lists. It offers the possibility to just generate the payloads as plain-text or to execute them inside...
  14. dEEpEst

    How to Upgrade Your XSS Bugs from Medium to Critical

    Credits: hakluke Hidden content
  15. Z

    XSS

    Buenas señ@res, tengo un pequeño problema, con la busqueda de subdominios y queria saber las herramientas que utilizan para esto, pues yo uso Sublist3r, masscan ademas de nmap, mucho mas rapido y mejor y mas masdns para los dns, ahora estoy mirando  https://github.com/guelfoweb/knock. Tambien...
  16. 1

    Exploits Veralite / Veraedge Router XSS / Command Injection / CSRF / Traversal

    Veralite and Veraedge routers / smart home controllers suffer from command injection, cross site request forgery, cross site scripting, code execution, directory traversal, and various other vulnerabilities. View the full article
  17. 1

    Exploits Securifi Almond 2015 Buffer Overflow / Command Injection / XSS / CSRF

    Securifi Almond 2015 suffers from buffer overflow, command injection, cross site scripting, cross site request forgery, and various other vulnerabilities. View the full article
  18. 1

    Exploits Dell KACE System Management Appliance (SMA) XSS / SQL Injection

    Dell KACE System Management Appliance (SMA) versions prior to 9.0.270 patch SEC2018_20180410 suffers from cross site scripting and remote SQL injection vulnerabilities. View the full article
  19. itsMe

    XSSCon - Simple XSS Scanner Tool

    Powerfull Simple XSS Scanner made with python 3.7 Hidden content Roadmap v0.3B: Added custom options ( --proxy, --user-agent etc... ) v0.3B Patch: Added support for ( form method GET ) v0.4B: Improved Error handling Now Multiple parameters for GET method is Supported
  20. 1

    Exploits phpKF 1.10 XSS / CSRF / SQL Injection

    phpKF version 1.10 suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities. View the full article
Back
Top