Last active
August 29, 2015 14:05
-
-
Save MiguelBel/e3c27fa4ac5fc60d11cb to your computer and use it in GitHub Desktop.
XSS in spanish politic party Foro Asturias
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Soy un aficionado a las auditorias de seguridad y he encontrado una vulnerabilidad en su web, permite ejecutar código javascript externo. | |
La prueba de concepto es esta url: | |
http://www.foroasturias.es/buscar/Hola');alert('xss | |
Para solucionarlo deben escapar correctamente los parámetros de consulta. | |
Un saludo. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Solved and answered 👍