BlackFan / client-side-prototype-pollution

Prototype Pollution and useful Script Gadgets

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Twitter Universal Website Tag gadget payload blocked by browsers (both Chrome and Firefox)

dexter-morgan opened this issue · comments

Hi this payload works for me in all tested browsers.
Check the HTTP response /i/adsct which returns an error, there should be twttr.conversion.loadPixels({}).

Sorry for "reopening" this, but it looks like this gadget no longer works in any browser: no XSS is triggered. Has it been fixed?

Yes, it looks like uwt.js was rewritten a few months ago and no longer contains the loadPixels function that was used in the gadget.

Thank you for confirming :)