owncloud.help: Text Injection

Disclosed: 2016-01-23 07:47:37 By geekh To owncloud
Unknown
Vulnerability Details
Hello i want to report a text injection and a missconfiguration of the 404 page which can be used in phishing Text injection can be used in phishing 404 page should not include attacker text The bug exists at : https://owncloud.help/test/%2f../It%20has%20been%20changed%20by%20a%20new%20one%20https://www.crowdcurity.com%20so%20go%20to%20the%20new%20one%20since%20this%20one as you can see attacker text is included "It has been changed by a new one https://www.crowdcurity.com so go to the new one since this one was not found on this server." Fix : just use a 404 page that don't include attacker text just as : hackerone.com,bugcrowd.com do (a 404 page that don't include any externel text hope you fix it Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 112304
  • State: Closed
  • Substate: resolved
Share this report