Member's Mark — XSS proofs

All against admin.membersmarkfans.com. The old mymembersmarkadmin.samsclub.com host is down, so the URLs in the filed reports no longer reproduce — these do.

  1. FileUpload.aspx — UserIdreported
    Reflected, attribute injection. Fires on load.
    https://admin.membersmarkfans.com/Platform1Landing/Pages/Invite/FileUpload.aspx?UserId=…
  2. ImageUpload.aspx — PortalIdqueued
    Same class, different page and parameter. Fires on load.
    https://admin.membersmarkfans.com/Platform1Landing/Pages/Invite/ImageUpload.aspx?PortalId=…
  3. interviewee-messages.html — Datequeued
    DOM XSS, GET only, no tokens. Fires on load.
    https://admin.membersmarkfans.com/…/interviewee-messages.html?MessageId=1&Date=…
  4. member-home.html — origin-unchecked postMessageopen
    No URL parameter involved; needs a window handle, so one click here. Affects 5 pages.
    → /pmxss/
  5. Welcome.aspx — RedirectUrlreported
    POST only (the field is empty on GET). ASP.NET tokens embedded statically.
    → /welcome/

Payload is alert(origin) in every case — it prints the target's own origin, which is what proves execution context.