I am new to InfoSec and am trying to learn and try things for myself. I am exploring vulnerabilities in phpBB version 2.0.15.
I have used OWASP ZAP to scan the site, and I have discovered
I can work out that the postorder parameter is exploited with JavaScript, and in this case, should just show an alert popup on the screen.
I am trying to replicate this myself, using the URL and seeing the popup in my browser, however i cant seem to manage.
When using the link im expecting to see the JavaScript alert, however nothing happens.
How do I make it work? / What am i doing wrong? / What am i supposed to do with this?
Thanks