<p>Introduction :</p><p>a Stored And a Reflected XSS Vulnerability In Profile Area In Tendoo CMS</p><p>Make CMS Vulnerable And Can Be Used For Stealing Admin Cookies And ....... .</p><p>######################</p><p> </p><p>Stored Xss In <a href="http://localhost/tendoo/index.php/account/update" rel="nofollow">http://localhost/tendoo/index.php/account/update</a> In First</p><p>Name and Last Name Inputs</p><p>Excute Java Script Codes And If Admin Or Any Body Come In Attacker Profile</p><p>When First Name And Last Name Loads</p><p>JavaScripts Code Will Be Excuted</p><p></p><p> </p><p><a href="https://i.leetfil.es/e992ad2d.jpg" rel="nofollow">https://i.leetfil.es/e992ad2d.jpg</a></p><p> </p><p>
暂无评论