Cross Site Scripting Vulnerability on Google Acquisition Waze (Video Attached)



Company  : Google Inc
Bug : Cross Site Scripting
Domain : www.waze.com

While searching Google Acquisitions to hunt bugs for Reward saw a Heading 

Google Bought Waze For $1.1B, Giving A Social Data Boost To Its Mapping Business
                                                                                             Ref : Techcrunch


So I created an account and inject some Malicious Java-script payload! Boom!!!
Click on image to Zoom

Reported to Google but it turned as Duplicate. (May be I was too late to report) 


Lesson Learned  : Whenever you find some bug report it as soon as possible 

But Finally found the Original Reporter 



Proof of Concept (Video):




No comments:

Post a Comment

Any Doubts ??
Don't wait till last Breath just Leave a Comment Below ;)

Hacking Articles for Free...