Web Hack List

Collected research

How To Own Every User On A Social Networking Site

Matt Johansen chains a DOM-based persistent XSS in a social network's profile tag field with missing authorization on the id parameter of the AddTag request. Because every user's id is public in their profile URL, a short injection calling an external script could be written into every profile's DOM, making the flaw wormable.

Record

Researcher
Matt Johansen
Published by
blog.whitehatsec.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Matt Johansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .