<div>Greetings!</div>
<div>Doing hard searches and working hard seeking for xss holes we finally found!<br><br>The new hole is in the description of the pic, you can put html encode chars like this.</div>
<div> </div>
<div>& l t ; meta http-equiv="refresh" content="0;url=<a href="http://suafakeaqui">http://suafakeaqui</a>" & g t ;</div>
<div> </div>
<div>&lt; means < (minus) or open tag.<br>&gt; means > ( more ) or close tag.</div>
<div> </div>
<div>So you can build great javascripts to stole cookies and whatever you want ;)</div>
<div> </div>
<div><strong>Proof of concept:</strong><br><br>My Profile: <a href="http://www.orkut.com/Album.aspx?uid=4196484633792069568">http://www.orkut.com/Album.aspx?uid=4196484633792069568</a> ( just a javascript with location.href='mypersonalwebsite.com
' )</div>
<div> </div>
<div>Thanks to Pedro Boara ( <a href="http://www.suspensa.info">http://www.suspensa.info</a> )</div>
<div> </div>
<div>Att;</div>
<div>Fábio N Sarmento<br>Programmer</div>
<div>São Paulo / Brazil</div>