Web Security | Web Hacking | Bug Bounty POC | Web Penetration Testing Tools

Friday, June 24, 2016

Cross Site Scripting in Hostinger

Hostinger is a free web hosting services provider and domain registrar.

Reproduction Steps :

1- Go to https://cpanel.hostinger.in/auth
2- Login to your account
3- Go to my profile and click on edit profile
4- Now change your name and set it to cross-site scripting payload (“><img src=x onerror=prompt(2);>).
5- Click save changes and payload will be executed












No comments:

Post a Comment