Full Disclosure mailing list archives

Adobe Web-Site Persistence XSS


From: asish agarwalla <asishagarwalla () gmail com>
Date: Tue, 1 Nov 2011 10:12:32 +0530

Title:
======
Adobe Web-Site Persistence XSS

Status:
========
Unpatched


Details:
========

1. Signin to adobe.com
2. Go to My information
3. Change Screen Name to
'><script>alert("xss");  or '><script>alert("xss");
4. Go to My adobe


@Asish (asishagarwalla () gmail com)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: