Persistent XSS
In Blogtags (reported, but not fixed)
In Grouplocation Tag and Group Website field (reported, but not fixed)
Reflective XSS
On Profile not found page
(already fixed)
Edit:
Workarround not acceptable works with other attack vector.
Same on Group not found page and so on.
Opera
Firefox
On Profilecontroller (unknown action issue) (reported, but not fixed)
http://houseofhackers.ning.com/profiles/profile/<here>
PoC Firefox
PoC Opera
Edit: Same on eventcontroller, ... and so on.
Workarround not acceptable.
Next one I found:
PoC
PoC Opera
PoC Firefox
PoC Firefox
.....
You need to be a member of House of Hackers to add comments!
Join this Ning Network