Full Disclosure mailing list archives
Re: BLOGGER XSS VULNERABILITY
From: Susam Pal <susam () susam in>
Date: Sun, 12 Aug 2007 22:39:02 -0700
On Aug 13, 2007 7:48 AM +0530 Valdis.Kletnieks () vt edu said: Obviously, your blog doesn't allow any users to comment...
Even if a blog allows users to comment, it is still not a vulnerability. As per the report, blogspot.com allows the JavaScript in the blog. JavaScript is *not* allowed in the comments. Regards, Susam Pal http://susam.in/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- BLOGGER XSS VULNERABILITY Daniele Costa (Aug 12)
- Re: BLOGGER XSS VULNERABILITY Susam Pal (Aug 12)
- Re: BLOGGER XSS VULNERABILITY Valdis . Kletnieks (Aug 13)
- Re: BLOGGER XSS VULNERABILITY Susam Pal (Aug 13)
- Re: BLOGGER XSS VULNERABILITY Harry Muchow (Aug 13)
- Re: BLOGGER XSS VULNERABILITY Valdis . Kletnieks (Aug 13)
- Re: BLOGGER XSS VULNERABILITY Susam Pal (Aug 12)