Sinisterly
Persistent XSS Vulnerability in White House Website - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Persistent XSS Vulnerability in White House Website (/Thread-Persistent-XSS-Vulnerability-in-White-House-Website)



Persistent XSS Vulnerability in White House Website - EVILKING - 11-05-2011

[Image: Untitled.png]

IMAGE LINK: http://evilking.0adz.com/Untitled.png
Alexander Fuchs, A German Security Researcher Discover Persistent XSS Vulnerability in Official website of White House. He said "The petition system is vulnerable. Every Petition i start or join will execute my code. I could join all petitions and my code will be executed on all users who visit the petition system."

The XSS Demo is here: https://wwws.whitehouse.gov/petitions/!/petition/security/WxgwM7DS
Advisory: http://vulnerability-lab.com/get_content.php?id=308



source: http://thehackernews.com/2011/11/persistent-xss-vulnerability-in-white.html


SAY THANKS!!OR BUY ME BEERCool



RE: Persistent XSS Vulnerability in White House Website - 1234hotmaster - 11-05-2011

why did you post it twice?


RE: Persistent XSS Vulnerability in White House Website - EVILKING - 11-05-2011

(11-05-2011, 07:42 AM)1234Darkmaster Wrote: why did you post it twice?

which one?


RE: Persistent XSS Vulnerability in White House Website - 1234hotmaster - 11-05-2011

oh nvm that was AOL Biggrin Biggrin


RE: Persistent XSS Vulnerability in White House Website - Proskill - 11-05-2011

Don't leech Things from skidforums

skidforums

(remove the point)


RE: Persistent XSS Vulnerability in White House Website - EVILKING - 11-15-2011

(11-05-2011, 10:40 AM)Proskill Wrote: Don't leech Things from skidforums

skidforums

(remove the point)
hey dude

i think i am not leech it from skidforums

in my post in end i tell you that source is thehackernews.com
and i can not found it on hackforums



RE: Persistent XSS Vulnerability in White House Website - iMarcus - 11-17-2011

First off, there is higher security for the white house than you can pull off to cover your tracks (this is down to the fact that the government has official rights to monitor everything associated with any incoming and outgoing connection to there electronically based systems and databases)

Secondly, Just attempting to do this would result in big consequences, this is not recommended at all unless you have permission to do so.

Thirdly, Highly illegal and stupid. There's finding vulnerabilities, and there is executing vulnerabilities.