Photobucket suffers from a cross site scripting vulnerability.
0e35e97015de926e364a868feedd4b6f1602bdd5e1c10088e355eafab2bc2c5d
# Date: 2.03.2012
# Author: Sony
# Web Browser : Mozilla Firefox
# PoC:
https://st2tea.blogspot.com/2012/03/photobucketcom-cross-site-scripting.html
..................................................................
Simple.
Step 1.
Our Profile:
Put our xss code in the fields: First name and Last name and ..save.
https://4.bp.blogspot.com/-I9QBe6Z9L9E/T1EhvEIEnvI/AAAAAAAAAqQ/WwB9tVeKMxM/s1600/bitprofile.JPG
Step 2.
Open page:
https://smg.photobucket.com/friendfinder
https://1.bp.blogspot.com/-CHp6f4fATvA/T1EmmTbcISI/AAAAAAAAAq0/NGCX-uzlYbo/s1600/invite.JPG
And press button invite friends and enjoy! We can see a persistent xss bug.
But it's not a critical bug.
https://1.bp.blogspot.com/-sp1z4JfHDKw/T1EigdYMneI/AAAAAAAAAqc/7_MxhIFCoUk/s1600/bit.JPG
https://3.bp.blogspot.com/-dqcyRCpCsRI/T1Eij84U_qI/AAAAAAAAAqo/ckJflJu4TdE/s1600/bit1.JPG
..................................................................
InSecurity.Ro
Because we care, we're security aware!