.. / CVE-2017-18024

Exploit for AvantFAX 3.3.3 - Cross-Site Scripting (CVE-2017-18024)

Description:

AvantFAX 3.3.3 contains a cross-site scripting vulnerability via an arbitrary parameter name submitted to the default URL, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.

Nuclei Template

View the template here CVE-2017-18024.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2017/CVE-2017-18024.yaml
Copy

References:

http://packetstormsecurity.com/files/145776/AvantFAX-3.3.3-Cross-Site-Scripting.html
https://nvd.nist.gov/vuln/detail/CVE-2017-18024
https://hackerone.com/reports/963798
https://github.com/NarbehJackson/Java-Xss-minitwit16
https://github.com/ARPSyndicate/kenzer-templates