Saturday, April 13, 2013

Kindeditor XSS bugs

1. find your target using Google Dork,

inurl:examples/uploadbutton.html

you can combine like this for looking specific domain,

inurl:prod_detail.php?id= site:.mn

2. click the url victim

ex,


3. click upload button, choose your html file as deface signature and copy the path and paste to url,

ex,


and press enter

No comments:

Post a Comment