This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in PHPAUCTION's register.php by injecting malicious JavaScript via the TPL_name and TPL_nick parameters. The payload triggers an alert dialog, confirming the XSS vulnerability.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:PHPAUCTION (version not specified)
No auth needed
Prerequisites:Access to the PHPAUCTION register.php page