Description
Fiverr Clone Script 1.2.2 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft URLs with script tags in the keyword parameter of search-results.php to execute arbitrary JavaScript in users' browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Mr Winst0n
References
www.exploit-db.com/exploits/46637 (ExploitDB-46637)
www.vulncheck.com/...ss-site-scripting-via-search-resultsphp (VulnCheck Advisory: Fiverr Clone Script 1.2.2 Cross-Site Scripting via search-results.php)