Reported a issue related to session cookies. http://help.dribbble.com/customer/portal/articles/1436528-responsible-security-disclosure-policy
Author: Osanda Malith Jayathissa
Acknowledged by Altervista
I usually don’t write about XSS issues in websites but since this was a hard hunt I thought of writing a bit. The web application was okay with user input but I did not give up. After some time I figured out that the “target” parameter in the login form was not properly sanitized and no CSRF tokens were used in the login process. Therefore I was able to build a successful POST XSS exploit. (more…)
Acknowledged by CyberGhostVPN
I did a big research on the CyberGhost website and I was able to find 21 security issues. For responsibly disclosing them I received a nice letter of thanks 😉