Skip to content

Comment on Deadsimple.me – Low Noise Single Page Websites

Comments

Howdy. I think this is vulnerable to cross-site scripting. For example: http://deadsimple.me/foobar/

Yup, the cookie isn't limited to your path. What's even worse, when logged in you can edit any page:

http://deadsimple.me/foobar/?edit

Well, you can edit pages which are NOT password protected from the owner. That's fine.

I tried to password-protect the page in question. It may not be working properly.

Alright, issue should be solved now. Try yourself! Thanks.

Well, that makes the XSS vulnerability kind of moot.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.