Attacker Value
Very High
(1 user assessed)
Exploitability
Very High
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
1

CVE-nu11-19-302021

Add MITRE ATT&CK tactics and techniques that apply to this CVE.
Execution
Techniques
Validation
Validated
Validated

Description

The Electric Billing Management System (by oretnom23) is suffering from XSS – DOM PHPSESSID hijacking vulnerability. The attacker can execute a remote payload and he can steal an active PHPSESSID, he can use for different malicious purpose.

Add Assessment

1
Ratings
  • Attacker Value
    Very High
  • Exploitability
    Very High
Technical Analysis

CVE-nu11-19-302021

href


Description:

The Electric Billing Management System (by oretnom23) is suffering from XSS – DOM PHPSESSID hijacking vulnerability.
The attacker can execute a remote payload and he can steal an active PHPSESSID, he can use for different malicious purpose.


  • Payload…
zd3ji%3c%2ftitle%3e%3cscript%3ealert(document.cookie)%3c%2fscript%3eoyc33
  • Vulnerable app about
http://192.168.1.180/electric_billing/?page=about

Reproduce:

href

Proof:

href

General Information

References

Exploit
The following exploit POCs have not been verified by Rapid7 researchers, but are sourced from: nomi-sec/PoC-in-GitHub.
Additional sources will be added here as they become relevant.
Notes: We will only add the top 3 POCs for a given CVE. POCs added here must have at least 2 GitHub stars.

Additional Info

Technical Analysis