I didn't find the first one anywhere through a search of
google.com, and I remember the second one had to do with the "Did you mean" suggestion, so if I put in speelin"><scrpit>alret("XSS")</scrpit>speelin it would output Did you mean spelling"><script>alert("CSS")</script>spelling ? and not check its own output. (speelin on the beginning and end because it corrects/highlights everything between the spelling mistake.
I never thought about that before, I'll look around for another PoC somewhere.
Edited 1 time(s). Last edit at 11/16/2006 09:31PM by Ghozt.