DISQUS

DISQUS Hello! (it)gossips - tech juice, daily. is using DISQUS, a powerful comment system, to manage its comments. Learn more.

Community Page

Jump to original thread »
Author

Massive HTML Injection Vulnerability

Started by buchin · 8 months ago

This could become a massive vulnerability since many sites or blogs out there allow user to post image on their article’s comment. As my small research, I found out that we could launch a HTML Injection, XSS and even CSRF attack to sites that vulnerable to this. Here is the PoC :%0 ... Continue reading »

0 comments

This thread has no comments yet.

Add New Comment

Returning? Login