Thursday, 17 October 2013

Shopify Mutiple Presistent XSS


Shopify Mutiple Presistent XSS 



First Login To Your Shopify account .


I Logged Into MY Shopify Acc
I Added A Product With Title As "><img src=x onerror=prompt(1)>
And Saved It I Went To Blog Post
I Got The XSS Popup

Here is my blog link :-
http://img-src-x-onerror-prompt1111.myshopify.com/products/img-src-x-onerror-prompt-1   [[ Now Removed Because 14 Days Tried Exceeded :p ]]






then in Discount Type .. I Selected " Off for Specific Product '' And
Selected the product named "><img src=x onerror=prompt(1)>

And I Saved IT .. I Got The XSS popup




Third Is In Upload Files Section
I Uploaded A Flash I Got The XSS Popup


Fourth Is In Also In Upload Files Section
I Uploaded A Html With "><img src=x onerror=prompt(1)>
I Opened It I got The XSS popup

Link :- http://cdn.shopify.com/s/files/1/0280/4199/files/asd.html?7



Finally  The Second Vulnerability Is Only Valid  .. I Got 500$  ^_^

Thanks To Shopify Team ":)




2 comments:

  1. A personal course includes the establishment of a professional store accompanied by personal training and professional consultation. shopify

    ReplyDelete
  2. I never thought I will come in contact with a real and potential hacker until I knew   brillianthckers800 at Gmail and he delivered a professional job,he is intelligent and understanding to control jobs that comes his way
    Contact him and be happy

    ReplyDelete