{"id":255,"date":"2012-06-06T16:26:40","date_gmt":"2012-06-06T16:26:40","guid":{"rendered":"http:\/\/epsilonlambda.wordpress.com\/?p=255"},"modified":"2013-07-24T09:18:49","modified_gmt":"2013-07-24T09:18:49","slug":"xss-in-snapdeal-com-2","status":"publish","type":"post","link":"https:\/\/securityresearch.cysecurity.org\/?p=255","title":{"rendered":"XSS in SnapDeal.com"},"content":{"rendered":"<p>Site: http:\/\/www.snapdeal.com<br \/>\nThreat\/Vulnerability: Cross site scripting a.k.a XSS, URL Redirection<br \/>\nSeverity : Moderate<br \/>\nAuthor: Karthik R a.k.a 3psil0nlambda<\/p>\n<p><strong>I have informed the owner (CEO) but got no response, acknowledgement of receipt of the mail.<br \/>\n<\/strong><br \/>\nAbout the Site:<\/p>\n<p>India&#8217;s fastest growing shopping site.<\/p>\n<p>Vulnerability:<br \/>\n*XSS a.k.a Cross site scripting<br \/>\n*URL Redirection<\/p>\n<p>Once found out the Vulnerability, it can be used in the following URL to create any attacks.<\/p>\n<p>*Installing malware in the name of Snapdeal.com and gain credit card and other important credentials<br \/>\n*Phishing URL Redirection, and gain login-ID and password<\/p>\n<p>URL used for crafting attacks:-<br \/>\n*http:\/\/www.snapdeal.com\/search?categoryId=0&amp;keyword=<strong>XSS<\/strong> &amp;vertical=all&amp;clickSrc=go_recent&amp;locId=0<br \/>\n*http:\/\/www.snapdeal.com\/products\/lifestyle-handbags-wallets?q=Brand:Jute Planet,A-maze&amp;sort=<strong>XSS<\/strong><\/p>\n<p>Greetz to side-effects, r4dc0re, lord crusader, team inject0r<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Site: http:\/\/www.snapdeal.com Threat\/Vulnerability: Cross site scripting a.k.a XSS, URL Redirection Severity : Moderate Author: Karthik R a.k.a 3psil0nlambda I have informed the owner (CEO) but got no response, acknowledgement of receipt of the mail. About the Site: India&#8217;s fastest growing shopping site. Vulnerability: *XSS a.k.a Cross site scripting *URL Redirection Once found out the Vulnerability,\u2026 <span class=\"read-more\"><a href=\"https:\/\/securityresearch.cysecurity.org\/?p=255\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"_links":{"self":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/255"}],"collection":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=255"}],"version-history":[{"count":1,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/255\/revisions"}],"predecessor-version":[{"id":357,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/255\/revisions\/357"}],"wp:attachment":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}