exploitdb
WORKING POC
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34660
This exploit demonstrates a cross-site scripting (XSS) vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5 by injecting a script tag into the 'name' parameter of the embed.php file. The PoC uses a simple alert to display the document.cookie, proving arbitrary script execution in the context of the affected site.
Classification
Working Poc 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the embed.php endpoint · User interaction to trigger the XSS payload
exploitdb
WRITEUP
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34657
The provided text describes a cross-site scripting (XSS) vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'category' parameter.
Classification
Writeup 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable web application
exploitdb
WORKING POC
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34662
This exploit demonstrates a reflected XSS vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5 by injecting a script tag into the 'id' parameter of the lyrics.php page. The PoC uses a simple alert to display the document cookie, proving arbitrary JavaScript execution.
Classification
Working Poc 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable lyrics.php endpoint
exploitdb
WORKING POC
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34663
This exploit demonstrates a reflected XSS vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5 by injecting a script tag into the 'key' parameter of the video_listing.php page. The PoC uses a simple alert to display the user's cookies, proving arbitrary JavaScript execution.
Classification
Working Poc 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable web application
exploitdb
WRITEUP
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34656
The provided text describes a cross-site scripting (XSS) vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5, where the 'pic_id' parameter in 'video_ad.php' is not properly sanitized. This allows arbitrary script execution in the context of the affected site.
Classification
Writeup 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable endpoint
exploitdb
WRITEUP
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34658
The provided text describes a cross-site scripting (XSS) vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5, where user-supplied input is not properly sanitized in the 'id' parameter of header1.php. No actual exploit code is included.
Classification
Writeup 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable web application
exploitdb
WRITEUP
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34661
This is a writeup describing a cross-site scripting (XSS) vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5. The vulnerability arises from improper sanitization of user-supplied input, allowing arbitrary script execution in the context of the affected site.
Classification
Writeup 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable web application
exploitdb
WRITEUP
VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34659
The provided text describes a cross-site scripting (XSS) vulnerability in x10 Media Automatic MP3 Search Engine 1.6.5, where user-supplied input is not properly sanitized. The vulnerability allows arbitrary script execution in the context of the affected site.
Classification
Writeup 90%
Target:
x10 Media Automatic MP3 Search Engine 1.6.5
No auth needed
Prerequisites:
Access to the vulnerable web application