attack in not an authorized user

Disclosed: 2016-02-16 20:00:32 By pisarenko To security
Unknown
Vulnerability Details
example (exit account) go to http://myfuneral.ru/hackerone.php your location https://hackerone.com/users/sign_in and Error 502 Ray ID: ***************** • 2016-01-19 19:31:49 UTC Bad gateway I think this was due to the fact that enrolled in the cookie with an invalid redirection ssesiyami (after authorization of the user was redirected to the link which is in hackerone.php, but this site does not do) короче все в сессию записалась трудная ссылка , которую hackerone.com не может нормально воспринимать , чтобы после авторизации направить пользователя по пути редикта
Actions
View on HackerOne
Report Stats
  • Report ID: 111676
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report