Skip to content

Instantly share code, notes, and snippets.

@MiguelBel
Created August 11, 2014 22:18
Show Gist options
  • Save MiguelBel/0b8f4b20cdbd2ff64817 to your computer and use it in GitHub Desktop.
Save MiguelBel/0b8f4b20cdbd2ff64817 to your computer and use it in GitHub Desktop.
Hola, he encontrado una vulnerabilidad en su web que permite ejecutar código javascript.
Sé que no es el departamento adecuado así que ruego remitan el presente email al departamento adecuado.
La prueba de concepto es:
URL => http://www.uimp.es/agenda-link.html?texto=hola%22%3E%3CIMG%20SRC=/%20onerror=%22alert%28String.fromCharCode%2888,83,83%29%29%22%3E%3C/img%3E
Un saludo.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment