Deadsimple.me – Low Noise Single Page Websites(deadsimple.me)
deadsimple.me
Deadsimple.me – Low Noise Single Page Websites
http://deadsimple.me
2 comments
Howdy. I think this is vulnerable to cross-site scripting. For example: http://deadsimple.me/foobar/
Yup, the cookie isn't limited to your path. What's even worse, when logged in you can edit any page:
http://deadsimple.me/foobar/?edit
http://deadsimple.me/foobar/?edit
Well, you can edit pages which are NOT password protected from the owner. That's fine.
I tried to password-protect the page in question. It may not be working properly.
Alright, issue should be solved now. Try yourself! Thanks.
Well, that makes the XSS vulnerability kind of moot.