Stored XSS in amazon drive

kminthein
qwerty
Published in
1 min readFeb 18, 2018

Copy from 2018 blog post again.

I want share about my finding in amazon drive link.

After i found stored xss in microsoft outlook i choose another random target is amazon drive.

You can find my previous blog post here Stored(Blind) XSS in Microsoft outlook.

OK let’s start….

I upload filename with ‘“><img src=x onerror=alert(document.domain)>.jpg extension.

But nothing happened in their website.

I think myself “What if i share this drive folder or file?”…..

OK let’s share this link and the results is amazing..

They fixed within just 6 hours. And i got nothing lol…… They have no bounty program.

That’s why Jeff Bezos is becoming world richest man haha 🙂

--

--