XSS Reflected - https://www.stopthehacker.com/

Disclosed: 2014-08-08 18:06:03 By dekeeu To stopthehacker
Unknown
Vulnerability Details
Hi. I want to report a Reflected xss vulnerability that I found in www.stopthehacker website and which can affect the safety of your users. This vulnerability allows an attacker to inject in web pages javascript content for sending malicious scripts to an unsuspecting user. This flaw can access any cookies, session tokens, or other sensitive information retained by victim's browser and used with that site. This flaw works only in IE browser. Link: http://www.stopthehacker.com/?"><script>alert(document.cookie)</script> Steps for reproduce this vulnerability: Open the link above in IE and you can see that my javascript function alert() was executed. Regards, Coltuneac Alexandru
Actions
View on HackerOne
Report Stats
  • Report ID: 9148
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report