[Vulnerability Report] Non-Persistent XSS on eBay.com

The following is my report on a serious vulnerability which i had discovered on eBay .com, for which i was also awarded a place at eBay Hall of Fame.

---Following is the email which i had sent to eBay Security Team---

Vulnerability Type: Non Persistent XSS 

Vulnerability Reproduction Steps(POC): 

1. Visit the Scope URL as mentioned above. 

2. Enter the following payload in the search field: "]};; <script>alert("XSS-By-Ak" )</script>

3. After the search our URL becomes the same as POC URL which delivers the XSS alert payload "XSS-By-Ak" 

System Details: Firefox 41 on windows 8.1 

Let me know if you require any other information, i will be happy to assist. 

Amit Kumar(Ak) 
-------------------------------------End of eMail------------------------------------- 


Amit Sangra

Author & Editor

Amit is a Security Engineer acknowledged by Google, Apple, Microsoft, eBay, Intel and other top companies for reporting security issues in their web services.


  1. The resultant record was extensively publicized for advertising functions . A bonus is a special feature of the actual recreation theme, which is activated when sure symbols appear in a w88 login winning mixture. Bonuses and the variety of bonus features range relying upon the sport. In different bonus rounds, the player is introduced with a number of} items on a display screen from which choose on}. As the player chooses items, quantity of|numerous|a selection of} credits is revealed and awarded.

  2. Much like players situated in British Columbia, residents of Manitoba are restricted to using the PlayNow.com platform. If future modifications are made, many believe that both Manitoba and British Columbia will broaden their respective markets in unison. The level spread represents the margin of factors in which 벳익스플로어 the favored group must win the game by to “cover the spread.” Bets on the point spread are normally offered at eleven to 10 odds. For example, a player must bet $11 to win $10 for a complete payout of $21 or $110 to win $100. There are currently over 15 states along with the District of Columbia that offer legal online sports playing.