CVE-2023-30212
MEDIUM NUCLEIourphp <= 7.2.0 - Cross-Site Scripting via /client/manage/ourphp_out.php
Title source: llmExploitation Summary
EIP tracks 15 public exploits for CVE-2023-30212. PoCs published by libasmon, VisDev23, kuttappu123. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a Docker environment and exploit for CVE-2023-30212, an XSS vulnerability in OURPHP <= 7.2.0. The exploit demonstrates a reflected XSS attack via the `/client/manage/ourphp_out.php` endpoint.
Description
OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.
Exploits (15)
This repository provides a Docker environment and exploit for CVE-2023-30212, an XSS vulnerability in OURPHP <= 7.2.0. The exploit demonstrates a reflected XSS attack via the `/client/manage/ourphp_out.php` endpoint.
This repository provides a Docker environment to replicate CVE-2023-30212, an XSS vulnerability in OURPHP. The PoC includes a Dockerfile and vulnerable application files, along with a payload to trigger the XSS.
This repository provides a Docker-based lab environment to demonstrate CVE-2023-30212, an XSS vulnerability in OURPHP <= 7.2.0 via the `/client/manage/ourphp_out.php` endpoint. The PoC includes setup instructions and a sample exploit URL.
This repository provides a proof-of-concept for CVE-2023-30212, an XSS vulnerability in ourphp 7.2.0 via the /client/manage/ourphp_out.php endpoint. The exploit leverages the 'out' parameter to inject malicious JavaScript when the 'ourphp_admin' parameter is set to 'logout'.
This repository provides a Docker-based PoC for CVE-2023-30212, demonstrating a Local File Inclusion (LFI) vulnerability in PHP that can lead to Remote Code Execution (RCE). The exploit uses `php://filter` to read and execute a malicious PHP file, creating a file in `/tmp` as proof of execution.
This repository provides a lab setup for CVE-2023-30212, an XSS vulnerability in OurPHP. It includes a Docker environment and a proof-of-concept exploit demonstrating the vulnerability via a crafted URL.
This repository provides a writeup and steps to reproduce a reflected XSS vulnerability in Ourphp version 7.2.0 via the 'out' parameter in the logout functionality. It includes Docker setup instructions and a proof-of-concept payload.
This repository provides a Docker environment to replicate CVE-2023-30212, an XSS vulnerability in OurPHP. The PoC demonstrates the vulnerability via a crafted URL that triggers a JavaScript alert.
This repository provides a detailed technical walkthrough for replicating CVE-2023-30212, an XSS vulnerability in OURPHP versions up to 7.2.0. It includes step-by-step setup instructions, a proof-of-concept payload, and references to external resources.
This repository provides a writeup for exploiting CVE-2023-30212, an XSS vulnerability in Ourphp 7.2.0. It includes setup instructions and a proof-of-concept payload for triggering the vulnerability.
This repository provides a Docker-based vulnerable environment and a proof-of-concept exploit for CVE-2023-30212, an XSS vulnerability in OURPHP <= 7.2.0. The exploit demonstrates the vulnerability via a crafted URL targeting the `/client/manage/ourphp_out.php` endpoint.
This repository provides a Docker-based lab environment to test CVE-2023-30212, an XSS vulnerability in OurPHP. The lab.sh script automates the setup of a vulnerable environment, including downloading and configuring the target software.
This repository contains a README describing CVE-2023-30212, an XSS vulnerability in OURPHP versions up to 7.2.0. No exploit code or Docker environment details are provided in the snippet.
The repository contains only a README.md file with minimal content, lacking any exploit code or technical details for CVE-2023-30212.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N