ANE CMS 1 Persistent XSS Vulnerability
Pratul Agrawal
# Vulnerability found in- Admin module
# email Pratulag@yahoo.com
# company aksitservices
# Credit by Pratul Agrawal
# Software ANE CMS 1
# Site p4ge http://demo.anecms.com/index.php
# Category CMS / Portals
# Plateform php
# Proof of concept #
Targeted URL: http://server/acp/index.php?p=cfg&m=links
In ADD LINKS Field provide the malicious script to store in the Database.
That is-
After completion Just Refres the page and the script get executed again and again.
#If you have any questions, comments, or concerns, feel free to contact me.