
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
An attacker needs to find the vulnerable parameter (mc=) and inject the JS code like: '><div id="aa
After that, the attacker must send the full URL with the JS code to the victim and inject their browser.
#Payload: company_search_tree.php?mc=aaa'><div id="aaaa