Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-25202 — A vulnerability was found in PHPgurukul visitor management system 1.0. it has been rated as problemic. Affected by the issue is some unknown functionality of the file search bar that called search-result.php and search-visitor.php . The vulnerability is Cross-Site-Scripting (XSS). | Kitploit
工具/GitHubGitHub/agampreet-singh/cve-2024-25202
Web Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubagampreet-singh/cve-2024-25202

CVE-2024-25202

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →

关于

A vulnerability was found in PHPgurukul visitor management system 1.0. it has been rated as problemic. Affected by the issue is some unknown functionality of the file search bar that called search-result.php and search-visitor.php . The vulnerability is Cross-Site-Scripting (XSS).

分享
查看仓库
12年前尚未审核

CVE-2024-25202

在PHPgurukul访客管理系统1.0中发现了一个漏洞。它被评为有问题的。该问题影响了文件搜索栏的某个未知功能,该功能调用了search-result.php和search-visitor.php。该漏洞是跨站脚本(XSS)漏洞。

使用方法

PHPGURUKUL中另一个漏洞发现是认证会话中的SQL注入。

登录

登录账户或通过SQL注入绕过认证后,我们需要转到右上角的搜索管理。

Payload

'"><svg/onload=confirm(/xsss/)>

image

正如您所见,我将在搜索会话中搜索代码。

image

XSS弹窗

根据场景,XSS漏洞在search-visitor或search-bar.php中有效。

PoC(概念验证)视频教程

https://github.com/Agampreet-Singh/CVE-2024-25202/assets/73707055/7479c8cf-b6b7-4659-9be9-beb9bdb2153b

下载工具