Google Blogspot, after the new look, is suffering of a bunch of strange XSSs.
I've found them without doing anything .... just by publishing my old XSSs.
The problem is in several part where you open the preview of the Themes (including the new one for the mobile).
After doing a faster test I've noticed that it works also in the comments area, so, you can try to send a stored XSS and move the blogadmin like a puppet in the various functionalities.
I've changed for *myself* the layout, via XSS, without problems. Quite funny and ... problematic. (I'm not opening the comments for now ... and it's not a problem since they are just a few of them xD).
I will not add more informations but it's so SIMPLE that you just need to copy/paste one of my latest posts, as is.
I'm so lucky ... sometimes ... even if in an useless way.
I've found them without doing anything .... just by publishing my old XSSs.
The problem is in several part where you open the preview of the Themes (including the new one for the mobile).
After doing a faster test I've noticed that it works also in the comments area, so, you can try to send a stored XSS and move the blogadmin like a puppet in the various functionalities.
I've changed for *myself* the layout, via XSS, without problems. Quite funny and ... problematic. (I'm not opening the comments for now ... and it's not a problem since they are just a few of them xD).
I will not add more informations but it's so SIMPLE that you just need to copy/paste one of my latest posts, as is.
I'm so lucky ... sometimes ... even if in an useless way.
Comments
Post a Comment