Home / exploitsPDF  

Redbus.in Open Redirection

Posted on 31 January 2012

_______ ________________ __ _____________ _______ _ _ \______ | _/_ \______ __ _ __ \_ __ / /_ / /_ / / |/ /| | / / ______ / / / | | / \_/ \_/ / /| < | | / / /_____/ / |__| \_____ /\_____ /____/ |__|_ |___| /____/ /\_/ / / / ------------------------------------------------------------------------------------------------------------------------------------------------- TITLE: REDBUS.IN URL REDIRECTION vendor: redbus.in Author: r007k17-w a.k.a Raghavendra Karthik.D Email: n4gb07@gmail.com My blog: http://shadowrootkit.wordpress.com/ Google Dork: © Pilani Soft Labs Pvt. Ltd. --------------------------------------------------------------------------------------------------------------------------------------------------- DEMO: REDBUS is India's first,largest,favourite bus ticket booking site.It got voted by FORBES among the top 5 hottest start ups in India. BUG URL: redirection bug in 'redirectURL' parameter. 1. https://www.redbus.in/SeatsNotAvailableRedirect.htm?redirectUrl=http://www.xssed.com ---------------------------------------------------------------------------------------------------------------------------------------------------------- gr33t1ngs to s1d3-3ff3cts,L0rd CrUs4d3r,3ps1lonl4mbd4,A1-w1n6( N17|< ),1nJ3ct0r t3am and all my friends

 

TOP