Advertisement
Guest User

Untitled

a guest
Oct 17th, 2018
72
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.57 KB | None | 0 0
  1. <img class="jss552" src="https://marketing-images-qc-***-prep.prep.t****.com/api/images/1ea9163b-dd9b-4a16-b37e-fbf54e4232ba" alt="BLAH1-FRONT_QUARTER_RIGHT"> <--- my data is BLAH1 .-FRONT_QUARTER_RIGHT is appended to the end
  2.  
  3.  
  4. i added "><script>alert(1)</script></ from a direct burp API call, bypassing client side controls
  5.  
  6. which resulted in:
  7.  
  8. <img class="jss199" src="https://marketing-images-qc-***-prep.prep.t*****.com/api/images/a42dcd60-9d11-435e-a60f-d7f0e3482ef7" alt="&quot;><SCRIPT>ALERT(1)</SCRIPT></-FRONT_QUARTER_RIGHT">
  9.  
  10. note: i have starred out the URL
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement