Exploits / Vulnerability Discovered : 2020-08-20 |
Type : webapps |
Platform : php
This exploit / vulnerability Elkarbackup 1.3.3 persistent crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
1- Go to following url. >> http://(HOST)/elkarbackup/login
2- Default username and password is root:root. We must know login credentials.
3- Go to "Jobs" and press "Add client" button.
4- Write XSS payload in "Name" section.
5- Press "Save" button.