Request: GET /?osCsid=%22%3E%3Ciframe%20src=foo%3E%3C/iframe%3E HTTP/1.0 Host:(removed)
Here's the problem <iframe src=foo></iframe> .
Answer text:
<html><head><title>Object moved</title></head><body> <h2>Object moved to <a href="http://www.(removed).co.uk/index.aspx?osCsid="><iframe src=foo></iframe>">here</a>.</h2> </body></html>
Reply link:
http://www.(removed).co.uk/index.aspx?osCsid="><iframe src=foo></iframe>
Which contains the content from the query string.
Basically, someone can send someone a link where your osCsid contains text that allows you to display the page in a different way. You must make sure that osCsid deactivates the input or filters it against things that may be like that. For example, I could provide a line that allows you to load any javascript I want, or make the page render completely different.
As a side note, it tries to redirect your browser to a page that doesn't exist.
source share