Cenzic 232 Patent
Paid Advertising
sla.ckers.org is
ha.ckers sla.cking
Sla.ckers.org
Where you should disclose your vulnerabilities. Go read RFPolicy if you want to do responsible disclosure, and go here for when all else fails. 
Go to Topic: PreviousNext
Go to: Forum ListMessage ListNew TopicSearchLog In
Paypal.com XSS - REDIRECT-Iframe injection
Posted by: Fugitif
Date: May 12, 2009 09:36AM

source:

http://nemesis.te-home.net/News/20090512_PayPal_again_vulnerable_to_XSS_.html


Options: ReplyQuote
Re: Paypal.com XSS - REDIRECT-Iframe injection
Posted by: Fugitif
Date: May 18, 2009 05:01PM

another xss on paypal and also on ebay

http://nemesis.te-home.net/News/20090518_PAYPAL_and_EBAY_still_Vulnerable_to_XSS__.html

Options: ReplyQuote
Re: Paypal.com XSS - REDIRECT-Iframe injection
Posted by: ma1
Date: May 18, 2009 06:14PM

The "cool" thing is that, since this is a DOM XSS (type 0), it is completely ignored by IE 8's XSS protection ;)

--
*hackademix.net*

There's a browser safer than Firefox... Firefox, with NoScript



Edited 1 time(s). Last edit at 05/18/2009 07:02PM by ma1.

Options: ReplyQuote


Sorry, only registered users may post in this forum.