Profile Picture

monstermom ('te)

Reputation: -2 [rate]

Joined: Feb, 2023

Last online:

<Hello

Badges

badge

Etc

Send Message

Threads List
Possible Alts

Activity Feed

Created a new thread : TESTtesteaewsw")+--+-


https://www.roblox.com/<script>alert(10)</script>its only test guys <:

deawdewadewa<script>dewdaewddaewdwed</script&gt;</p>

Replied to thread : [CW] Sirweeb - Skidding, questionable code


https://forum.wearedevs.net/images/avatars/99921_1692935196996.pharpng

https://forum.wearedevs.net/images/avatars/99921_1692935196996.pharpng

Replied to thread : WeAreDevs on an AIO Screen


https://javascript:alert(10)

 

Commented to thread : What ssd size should I get to save games?


Do you know what is bug bounty bro?

Replied to thread : What ssd size should I get to save games?


I found an xss stored vulnerability

 

 

When you fetch a new Discord image link and modify the name of the image and put javascript html or css code, it will work fine

When you put an image link, a new class will be created, which is not protected. The programmer did not focus on filtering this class

test: httpjavasript:alert(10)//cdn.discordapp.com/attachments/1021469572391505920/1099287799930302525/<button onclick=alert(1)>test</button>.png

 

 

my paypal : ahmdnaser1232@gmail.com pls donate me 10 if you can <:
Also, there is a file upload loophole that I found. Believe me, I can upload any file, but if it is similar to the word jpg, your code has a problem.