Adiscon loganalyzer v.4.1.13 cross site scripting Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2023-08-04 |
Type : webapps |
Platform : php
This exploit / vulnerability Adiscon loganalyzer v.4.1.13 cross site scripting is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
# Date: 2023.Aug.01
# Exploit Author: Pedro (ISSDU TW)
# Vendor Homepage: https://loganalyzer.adiscon.com/
# Software Link: https://loganalyzer.adiscon.com/download/
# Version: v4.1.13 and before
# Tested on: Linux
# CVE : CVE-2023-36306
There are several installation method.
If you installed without database(File-Based),No need to login.
If you installed with database, You should login with Read Only User(at least)