Reflected XSS on ssl-ccstatic.highwebmedia.com via player.swf
Medium
C
Chaturbate
Submitted None
Actions:
Reported by
nahamsec
Vulnerability Details
Technical details and impact analysis
Hey there,
There's a SWF based XSS on ssl-ccstatic.highwebmedia.com. You may want to update/remove the file.
#POC
https://ssl-ccstatic.highwebmedia.com/jwplayer/player.swf?playerready=alert(document.domain)
Thanks,
Ben
## Impact
#
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected