Manual Approval Thread

Questions or requests about submissions
ant4r3ja
Posts:7
Joined:Mon May 06, 2019 1:07 pm
Re: Manual Approval Thread

Post by ant4r3ja » Wed May 08, 2019 8:13 am

824296
824300
824304
824310

thanks

ant4r3ja
Posts:7
Joined:Mon May 06, 2019 1:07 pm

Re: Manual Approval Thread

Post by ant4r3ja » Wed May 08, 2019 11:49 am

824340
824341
824342
824343
824344
824345
824348
824350
824351
824352
824353
824354
824355
824356
824357
824358
824359
824360

ant4r3ja
Posts:7
Joined:Mon May 06, 2019 1:07 pm

Re: Manual Approval Thread

Post by ant4r3ja » Wed May 08, 2019 11:52 am

824361
824362
824363
824364
824365
824366
824367
824368
824369
824370
824371
824372
824373
824374
824375
824376

thanks

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Manual Approval Thread

Post by x1admin » Thu May 09, 2019 7:09 am

approved

cosmoio
Posts:9
Joined:Sat Apr 20, 2019 12:45 pm

Re: Manual Approval Thread

Post by cosmoio » Thu May 09, 2019 7:46 pm

Hey,

I was wondering about: 822069. This is a reflected XSS based on a JSONP flaw on a service provided by a certain telecorporation. The JS itself won't be executed on that domain but can be executed somewhere else, e.g. via remote script injection on a different website <script src=telecorp.com/jsonp=..evil js />, there might even be the chance to do reflected downloading of malware. To me this is a severe issue.
You rejected it because, apparently, it's not reproducible. Did you have a look at my JSFiddle proving that this would work?

Can you tell me what your thoughts on this are, thank you?

Cheers,
cosmo

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Manual Approval Thread

Post by secuninja » Fri May 10, 2019 11:49 am

825869

thx

ant4r3ja
Posts:7
Joined:Mon May 06, 2019 1:07 pm

Re: Manual Approval Thread

Post by ant4r3ja » Sat May 11, 2019 4:27 pm

825136
825137
825138
825139
825140
825141
825142
825143
825144
825145
825146

thanks

metamorfosec_id
Posts:269
Joined:Mon Apr 30, 2018 7:35 am

Re: Manual Approval Thread

Post by metamorfosec_id » Mon May 13, 2019 3:04 am

Websites below are accessible:
827448
827449
827450
827451
827452
827453
827454
827455
827456
827457

Thank you...

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Manual Approval Thread

Post by x1admin » Mon May 13, 2019 8:23 am

approved

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Manual Approval Thread

Post by secuninja » Tue May 14, 2019 4:13 am

827849
thx

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests