URL: https://paypal.me/pages/countries
Normal request and response:
I added Referer header and I saw it. Payload:
https://nsa.gov
Request and response:
Browser:
If click a country, redirect nsa.gov (Redirect vulnerability)
I tried XSS payload but there is csp. Payload :
Request and response:javascript:alert(document.domain);
Browser and csp:
I thought about using internet explorer because of csp.
but this payload did not work in ie (syntax error). I found another payload:
javascript:alert(document.domain); https://google.com/
Video:
But this vulnerability is out of scope so I did not earn money :(
don't give up buddy!
ReplyDeletenice catch mate
ReplyDeleteHappy Hacking
that's great ,
ReplyDeletetry using flash + 302 redirection with spoofed referer header