Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Yet another (unpaid and unfixed) Paypal XSS
From: samuel alp <samuelalp95 () gmail com>
Date: Thu, 13 Jun 2013 11:14:56 +0200

Hi People

Found a XSS on german Paypal website last week and reported it exactly 7
days ago.
Their response was one we very well know
Another researcher already discovered the bug.

So, someone else found the Vulnerability before me and reported it.
Fine, looks like I was too slow. I can live with that.

Now, i received an answer exactly 7 Days ago. That means they had more than
a week to fix this

https://www.paypal.de/Einkaufswelt/H%C3%A4ndlerverzeichnis/?c="; ||
alert('XSS') || "

All they'd have to do is escape quotation marks or remove them since
they're not used anyways.
The Approximate time that takes is ~15 Seconds.

I am amazed by how long it takes some huge companys to close holes in their

Samuel Alp
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Yet another (unpaid and unfixed) Paypal XSS samuel alp (Jun 13)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]