Content Spoofing

Disclosed: 2016-06-19 12:03:22 By bajrangbaan To nextcloud
Unknown
Vulnerability Details
Hi i got content spoofing vulnerability . Content spoofing, also referred to as content injection or virtual defacement, is an attack targeting a user made possible by an injection vulnerability in a web application. POC Link :- https://nextcloud.com/.htacess%20THIS%20IS%20CONTENT%20SPOOFING Possible Fix: URL Encode spaces to %20 which will convert spoofing content look like link Cheers! Ashish Pathak
Actions
View on HackerOne
Report Stats
  • Report ID: 145374
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report