Jump to content

PrimaryUpload


Recommended Posts

Cross Site Scripting:

There is Cross Site Scripting if the Expect header contains code.

 

Cross Site Scripting:

There is Cross Site Scripting if you submit code in the drop down menu in Step 2.

 

Cross Site Scripting:

There is Cross Site Scripting if your email address contains code.

 

Cross Site Scripting:

There is Cross Site Scripting on the 404 page.

http://www.primaryupload.com/<marquee><h1>vulnerable</marquee>

 

Drop Down Menu:

If you edit the drop down menu in Step 2 you can submit arbitrary values.

 

Null User:

You can register a null FileKey.

Link to comment
Share on other sites

  • 3 weeks later...

If you go to

    http://primaryupload.com/media/process.php

you get a bunch of errors that give the user a pretty good idea of how your 'process.php' script works...

Probably the best way to fix it is to change the index file in /media/ to something else...

or you could turn off error messages...

BTW I like how short you were able to make the 'process' script!  ;)

Link to comment
Share on other sites

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.