Vulnerabilities
1. ‘bit.ly ‘service: allows one to send tweets with shortened URLs
• Reflected Cross-Site Scripting in the “url” query parameter. Patched
• Reflected Cross-Site Scripting in the keywords parameter. Patched
• Reflected POST Cross-Site Scripting in the username field of the login page. Patched
• Persistent Cross-Site Scripting in the content-type field of the URL info page. Patched
2. HootSuite: used to send tweets, direct messages and follow/unfollow other users from multiple Twitter accounts. It uses Username/Password authentication to utilize the Twitter API.
• Reflected Cross-Site (XSS) in the “add-account” page. Patched
3. TwitWall: used to send tweets and follow/unfollow other users. Uses OAuth authentication token to utilize the Twitter API (Application Programming Interface).
• Persistent Cross-Site (XSS) in TwitWall entry view page. Patched
4. BigTweet: used to send tweets from any web page by using a bookmarklet. Uses Username/Password authentication to utilize the Twitter API.
• Cross-Site Request Forgery in BigTweet ‘upate.json’. Patched
5. TwitSnaps (Note: dead link): Cross-Site vulnerabilities
6. TwitPic: used to send tweets by uploading new photos, sending them via email, or posting comments on existing photos. Uses Username/Password authentication to utilize the Twitter API.
• Cross-Site request forgery in the Email PIN settings pages. Patched
• Cross-Site Request Forgery in the comments form. Patched
• Persistent Cross-Site Scripting in the TwitPic profile page. Patched
7. yfrog: used to send tweets by uploading new photos, or posting comments on existing photos. Uses OAuth authentication method to utilize the Twitter API.
• Reflected Cross-Site Scripting in the Upload and Search pages. Patched
8. Twitterfall: used to send tweets, replies or follow other twitter users. Uses OAuth authentication method to utilize the Twitter API.
• DOM Based Cross-Site Scripting in the main page. Patched
9. Twellow: used to follow and unfollow other twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Reflected POST Cross-Site Scripting in the Contact page. Patched
10. Twitiq: used to send tweets, direct messages and follow/unfollow other Twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Cross-Site Request Forgery and Cross-Site Scripting in jsonp.php. Patched
11. Twitturly: used to send tweets to other Twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Persistent Cross-Site in Twitturly URLs view page. Patched
12. TweetGrid: used to send new tweets and reply to other Twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Reflected Cross-Site in the Search page. Patched
13. Brightkite: used to send new tweets and reply to other Twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Reflected Cross-Site in the "Person not found" page. Patched
14. TweetMeme: used to send new tweets and reply to other Twitter users. Uses OAuth authentication method to utilize the Twitter API.
• Reflected Cross-Site in the Search page. Patched
15. Slandr: used to send tweets, direct messages and follow/unfollow other Twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Cross-Site Request Forgery in main update page. Patched
• Reflected POST Cross-Site in the Search page. Patched
16. HelloTxt: used to send tweets to other Twitter users. Uses Username/Password authentication to utilize the Twitter API.
• Persistent Cross-Site in HelloTxt profile page. Patched
17. Mobypicture: used to send tweets by uploading new photos, or posting comments on existing photos. Uses Username/Password authentication to utilize the Twitter API.
• Persistent Cross-Site in mobypicture picture view page. Patched
18. tr.im: used to send tweets with the shortened URLs through a form on their website. Uses OAuth authentication method to utilize the Twitter API.
• Persistent Cross-Site in tr.im Referrer statistics page. Unpatched
19. Talker: used to send tweets, direct messages and follow/unfollow other Twitter users. Uses OAuth authentication method to utilize the Twitter API.
• Cross-Site Request Forgery in the update forms. Patched
• Reflected POST Cross-Site in the Subject page. Patched
[Back to top]