#9
(14 January, 2020 - 07:58 PM)Pentester708 Wrote: Show More
This can be said as Weak Password Policy and is listed in the OWASP Top 10

Site:

Did a Stored XSS Went Well
So you can see the username and password in the screen itself
Go Have Fun
Btw you can only upload jpg,jpeg
No option to upload a php shell
Either try for the exif data via image or the modified name shit

Note: Only for educational purpose
gjddjgd