PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting-CVE-2019-7437


*******************************************************************************************
# Exploit Title: PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field
# Date: 30.12.2018
# Site Title : Opensource Classified Ads Script
# Vendor Homepage: https://www.phpscriptsmall.com/
#Vendor Software: https://www.phpscriptsmall.com/product/professional-classified-ads-script/
# Software Link: http://198.38.86.159/~classic/
# Category: Web Application
# Version: 3.2.2
# Exploit Author: Vikas Chaudhary
# Contact: https://www.facebook.com/profile.php?id=100011287630308
# Web: https://gkaim.com/
# Tested on: Windows 10 -Firefox ,
# CVE-2019-7437
*****************************************************************************************

## VENDOR SUMMARY :- PHP Scripts Mall Pvt. Ltd. is a professional software selling portal offering wide range of innovative. PHP Scripts Mall is a leading business and technology firm with 12 years of successful track record in completion and implementation of numerous projects in various
verticals and domains.. It has 300 plus PHP scripts ready to buy.


## Vulnerability Description=> Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it.
****************************************************************************************
—————————————————— .
Proof of Concept:-
——————————————————-
1. Go to the site ( http://198.38.86.159/~classic/) .
2- In search box paste this script.


7-You will have a popup=> /VIKAS/

Comment Please