Member's Mark — XSS proofs
All against admin.membersmarkfans.com. The old
mymembersmarkadmin.samsclub.com host is down, so the URLs in the filed reports no
longer reproduce — these do.
- FileUpload.aspx —
UserIdreported
Reflected, attribute injection. Fires on load.
https://admin.membersmarkfans.com/Platform1Landing/Pages/Invite/FileUpload.aspx?UserId=…
- ImageUpload.aspx —
PortalIdqueued
Same class, different page and parameter. Fires on load.
https://admin.membersmarkfans.com/Platform1Landing/Pages/Invite/ImageUpload.aspx?PortalId=…
- interviewee-messages.html —
Datequeued
DOM XSS, GET only, no tokens. Fires on load.
https://admin.membersmarkfans.com/…/interviewee-messages.html?MessageId=1&Date=…
- member-home.html — origin-unchecked
postMessageopen
No URL parameter involved; needs a window handle, so one click here.
Affects 5 pages.
→ /pmxss/
- Welcome.aspx —
RedirectUrlreported
POST only (the field is empty on GET). ASP.NET tokens embedded statically.
→ /welcome/
Payload is alert(origin) in every case — it prints the target's own
origin, which is what proves execution context.