Deadsimple.me – Low Noise Single Page Websitesdeadsimple.me 18 pointscorruptnetwork15 years ago8 commentsSaveHideCopy link On HNComments−sweis15yHowdy. I think this is vulnerable to cross-site scripting. For example: http://deadsimple.me/foobar/−ElbertF15yYup, the cookie isn't limited to your path. What's even worse, when logged in you can edit any page:http://deadsimple.me/foobar/?edit−corruptnetworkOP14yWell, you can edit pages which are NOT password protected from the owner. That's fine.−sweis14yI tried to password-protect the page in question. It may not be working properly.−corruptnetworkOP14yAlright, issue should be solved now. Try yourself! Thanks.−sweis14yWell, that makes the XSS vulnerability kind of moot.−hollerith14yHow is this different from Jottit?−corruptnetworkOP14yJottit is overfeatured.
Comments
Howdy. I think this is vulnerable to cross-site scripting. For example: http://deadsimple.me/foobar/
Yup, the cookie isn't limited to your path. What's even worse, when logged in you can edit any page:
http://deadsimple.me/foobar/?edit
Well, you can edit pages which are NOT password protected from the owner. That's fine.
I tried to password-protect the page in question. It may not be working properly.
Alright, issue should be solved now. Try yourself! Thanks.
Well, that makes the XSS vulnerability kind of moot.
How is this different from Jottit?
Jottit is overfeatured.