Category: Resolved

XSS, arc.help.yahoo.com, Captcha Form, CWE-79, CAPEC-86, Cross Site Scripting, Resolved

XSS in arc.help.yahoo.com at captchaView parameter URL https://arc.help.yahoo.com/arc/arc.php “Please use this form to report the error you are experiencing.” The Form once contained a Captcha Form to prevent Bots and Spam from Submitting the Form. The Form was submitted with a POST containing the XSS in the captchaView Parameter using a Double-URL encoded expression.. POST..&captchaView=visual%2522%253balert%25281%2529%252f%252f…In […]

XSS, homes.yahoo.net, Cross Site Scripting, Javascript Injection, CWE-79, CAPEC-86, PoC, Resolved

PoC Summary The Mortgage Calculator in homes.yahoo.net was vulnerable to Reflected Cross Site Scripting (RXSS) in multiple parameters. Reported to Y! Security in October 2013 and more recently resolved, this PoC was outside the Scope of the Y! Bug Bounty Program.  Y! Bug Bounty Scope XSS in homes.yahoo.net The domains and properties below are in […]

Stored DOM XSS, www.ebay.com, Search Breadcrumb, Javascript Injection, Cookie Sink, Resolved

Stored DOM XSS in eBay Search Bread Crumb PoC Summary Stored XSS in www.ebay.com at Search Breadcrumb using multiple Parameters & Cookie Sinks via URL to evade XSS Neutering Routines.  Stored XSS in www.ebay.com at Search Breadcrumb Description The Search Breadcrumb in www.ebay.com is dynamically generated based on User Navigation. The Search Terms, Search Breadcrumb […]

linkedin.com, XSS, Cross Site Scripting, CWE-79, CAPEC-86, Javascript Injection, Resolved

Resolved: XSS in trk parmeter of www.linkedin.com as an authenticated user. Reported to security@linkedin.com on June 11, 2013 and resolved today, August 18, 2013. PoC URLhttp://www.linkedin.com/today/?trk=today_home_top_today_control</script><script>alert(1)</script>MATCH ON:fs.config({“failureRedirect”:”http://www.linkedin.com/nhome/”,”xhrHeaders”:{“X-FS-Origin-Request”:”/today/?trk=today_home_top_today_control</script><script>alert(1)</script>”,”X-FS-Page-Id”:”pulse-top-news”}});REQUIRED: Logged In User XSS in linkedin.com Commentary: LinkedIn has a Vulnerability  Rewards Program which results in sending a T-Shirt, which is ridiculous. Instead, its suggested that Linked In […]

redhat.com, XSS, Cross Site Scripting, CWE-79, CAPEC-86, Javascript Injection, Resolved

Resolved: Search Query XSS in www.redhat.com Reported a while back and fixed more recently. Does your Site have a Search Box? Test for XSS.Does your Site use Omniture Tracking Code? Test for XSS. Once upon a time, www.redhat.com had Search Form XSS in the q Param due to the “old and vulnerable Omniture Code” that allowed […]

mail.discoverbing.com, XSS, Cross Site Scripting, CWE-79, CAPEC-86, Javascript Injection, Resolved

Resolved: XSS in mail.discoverbing.comReported Q2/2012, Resolved Q4/2012 Once upon a time, mail.discoverbing.com had multi-param XSS allowing all modern User Agent XSS Neutering Routines to be evaded. Resolved: XSS in mail.discoverbing.com

bing.com, XSS, Cross Site Scripting, CWE-79, CAPEC-86, Javascript Injection, Resolved

Resolved: XSS in www.bing.com at WeatherReported Q1/2013, resolved Q2/2013 The maptype and mapcat params reflected the JSI from the Server into the Browser. Since multiple Parameters could be combined, all modern User Agent Neutering Routines could be evaded. PoC URL was http://www.bing.com/weather/maps?q=weather&unit=3&FORM=DTPWEO&qpvt=3&mapview=detail&mapcat=1&maptype=’+prompt(9)+’. Resolved: XSS in www.bing.com in Maps

linkedin.com, XSS, Javascript Injection, Ad CDN Code, CWE-79, CAPEC-86, Cross Site Scripting, Resolved

Resolved: XSS in www.linkedin.comReported Q2/2012, Resolved Q2/2012 Thinking about Inlining some Ad CDN Code in your WebSite?Think Again.. its probably a bad move.. LinkedIn was foolish enough to Inline Javascript Code from the DoubleClick Ad CDN operated by Google. Initially Reported to Google in October 2010, XSS in DoubleClick at the time was “Out of […]