发新话题
打印

[转载]Yahoo Global XSS (login page)

[转载]Yahoo Global XSS (login page)

信息来源:Zuso Security

As you know, Yahoo is a well-known website in the world. We found that there are some XSS vulnerabilities by encoding the HTML code twice in the URI. We have notified the vendor on 4.24 already.

POC: Link

Enter any username and password you like, and then submit it, you'll see what happen.

The original advisory is located at http://www.zuso.org.tw/index.php?option=com_content&task=view&id=32&Itemid=1

Zuso Security is a group which is focus on web-based security in Taiwan.

Zuso Security -
vuln_AT_zuso.org.tw (vuln info only)
http://www.zuso.org.tw/
irc.zuso.org.tw #zuso (SSL tunnel: port 994)
曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题