[RESOLVED] youtube xss
Posted: Wed Aug 23, 2017 12:43 am
Noscript is blocking hovercards today...
Code: Select all
[NoScript InjectionChecker] JavaScript Injection in youtube.watch&origin=https://www.youtube.com&usegapi=1&jsh=m;/_/scs/abc-static/_/js/k=gapi.gapi.en.ellQXbSf-LI.O/m=__features__/am=AAg/rt=j/d=1/rs=AHpOoo9jm0At0b0B7I7G3MSvlepU00mZfA#id=I0_1503447298551&parent=https://www.youtube.com&pfname=&rpctoken=37236279
(function anonymous() {
_/scs/abc-static/_/js/k==gapi.gapi.en.ellQXbSf-LI.O/m==__features__
})
[NoScript XSS] Sanitized suspicious request. Original URL [https://apis.google.com/u/0/_/hovercard/internalcard?p=36&hl=en_US&p=36&ytid=UCpaPpDzDUTzYm0t4Pa5h28Q&src=youtube.watch&origin=https%3A%2F%2Fwww.youtube.com&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.ellQXbSf-LI.O%2Fm%3D__features__%2Fam%3DAAg%2Frt%3Dj%2Fd%3D1%2Frs%3DAHpOoo9jm0At0b0B7I7G3MSvlepU00mZfA#id=I0_1503447298551&parent=https%3A%2F%2Fwww.youtube.com&pfname=&rpctoken=37236279] requested from [https://www.youtube.com/watch?v=nYqqwsF3R04]. Sanitized URL: [https://apis.google.com/#17041864594364198338].