Open Redirection Found in users.whisper.sh
W
Whisper
Submitted None
Actions:
Reported by
hackedbrain
Vulnerability Details
Technical details and impact analysis
I found that one of your subdomains users.whisper.sh is vulnerable to open redirection.
POC: `http://users.whisper.sh//google.com/%2f..`
Response:
```
HTTP/1.1 303 See Other
X-Powered-By: Express
Location: //google.com/%2f../
Set-Cookie:
CM; Path=/; HttpOnly
Date: Sat, 19 Aug 2017 14:22:50 GMT
Content-Length: 34
Via: 1.1 google
Redirecting to //google.com/%2f../
```
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$30.00
Submitted
Weakness
Open Redirect