11th April 2015, 10:10 AM
Found a vulnerability it oldcp_api, it's not a serious one. But still Damen you should patch it.
http://blizzard.api.play.oldcp.biz/oldcp_api/login.php?Username=<script>alert("Got to love XSS")</script><h1>TimeLock rocks</h1>
http://blizzard.api.play.oldcp.biz/oldcp_api/login.php?Username=<script>alert("Got to love XSS")</script><h1>TimeLock rocks</h1>
Daymen
Administrator

5,165 posts
37,117
Seen 16th December 2024
11th April 2015, 10:38 AM
Client's browsers don't run javascript or parse html from that resource when logging in via oldcp, it is no threat.