
07.12.2007, 00:40
|
|
Постоянный
Регистрация: 23.09.2007
Сообщений: 416
Провел на форуме: 1781065
Репутация:
869
|
|
XSS On Ebay.com
I am still Fugitif and now I want to show you how can work one vulnerable XSS Alert Bug on Ebay.com.
To be more precise our link now is http://togo.ebay.com
Ok..My XSS alert can be found here http://togo.ebay.com/affiliates/create/
I go to select one version and I crush above
and immediately later click "I WANT THIS ONE"
In the square where asks FOR "ID" I put some string like this
Код:
"><script>alert(document.cookie)</script>
and click "Browse"
Now we cannot do anything else other than to use the search with our magic string
Код:
"><script>alert(document.cookie)</script>
My Result ? !
That's all .... have fun ppl
/Fugitif
|
|
|