Намедни собрался поискать задачи в архиве, но столкнулся с багом(фичей). При поиске "ready" мне выдает задачу розетки. Что пошло не так?
№ | Пользователь | Рейтинг |
---|---|---|
1 | tourist | 3757 |
2 | jiangly | 3647 |
3 | Benq | 3581 |
4 | orzdevinwang | 3570 |
5 | Geothermal | 3569 |
5 | cnnfls_csy | 3569 |
7 | Radewoosh | 3509 |
8 | ecnerwala | 3486 |
9 | jqdai0815 | 3474 |
10 | gyh20 | 3447 |
Страны | Города | Организации | Всё → |
№ | Пользователь | Вклад |
---|---|---|
1 | maomao90 | 171 |
2 | awoo | 165 |
3 | adamant | 163 |
4 | TheScrasse | 159 |
5 | maroonrk | 155 |
6 | nor | 154 |
7 | -is-this-fft- | 152 |
8 | Petr | 147 |
9 | orz | 145 |
9 | pajenegod | 145 |
Название |
---|
Further investigation: depending on the selected archive task page, different tasks are shown. But still not related to the
ready
theme.Auto comment: topic has been translated by KhB (original revision, translated revision, compare)
The same for word "class":
Auto comment: topic has been updated by KhB (previous revision, new revision, compare).
Автокомментарий: текст был обновлен пользователем KhB (предыдущая версия, новая версия, сравнить).
Try this payload on handle search:
<script\x20type="text/javascript">javascript:alert(1); ,
it should give "no such user" while it gives an error page. Might be vulnerable, I am not a tester. I was afraid to ask this in a post seeing a lot of downvotes in one of my posts.
Also words "remove", "click", "response", "function", "alert", "type", "toggle" and "codeforces" gives same result. Even parts of the link "sta.codeforces.com/s/" works in the same way.
It is really strange, that it works only on problemset page and gives only the first problem.