Loading HuntDB...

Stored XSS in photos_user_map.gne

High
F
Flickr
Submitted None

Team Summary

Official summary from Flickr

The Flickr map page was inadequately escaping the name of groups when browsing the map of a group's photos.

Reported by keer0k

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$3263.00

Submitted

Weakness

Cross-site Scripting (XSS) - Stored