Skip to content

Commit bc38890

Browse files
authored
Merge pull request KathanP19#48 from Virdoexhunter/master
adding param poll
2 parents 6ed5122 + ff31f58 commit bc38890

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
Hi Guys,
2+
3+
Though it is not severe bug.But still some organizations take this seriously.
4+
5+
Steps :
6+
7+
1.Browse through your target.
8+
say https://target.com
9+
2.Find a article or blog present on target website which must have a link to share that blog on different social networks such as
10+
Facebook,Twitter etc.
11+
3.Let's say we got and article with url:
12+
https://taget.com/how-to-hunt
13+
then just appened it with payload ?&u=https://attacker.com/vaya&text=another_site:https://attacker.com/vaya
14+
so our url will become
15+
https://taget.com/how-to-hunt?&u=https://attacker.com/vaya&text=another_site:https://attacker.com/vaya
16+
4.Now hit enter with the abover url and just click on share with social media.
17+
Just observe the content if it is including our payload i.e. https://attacker.com
18+
Then it is vulnerable or else try next target.
19+
20+
References:
21+
https://hackerone.com/reports/105953
22+
Google
23+
24+
You can finde me here
25+
https://twitter.com/KenAdams000

0 commit comments

Comments
 (0)