Bugtraq mailing list archives

fotolog xss


From: absamu () gmail com
Date: 11 May 2007 01:47:33 -0000

example:
http://www.fotolog.com/all_photos.html?user=[code]

http://www.fotolog.com/all_photos.html?user=%3Ch1%3EXSS%3C/h1%3E

bye


Current thread: