[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-disclosure] Baidu XSS Zero Day



Baidu.com is the bigest search engineen provider in China. After
been hacked by Iran Cyberarmy. There is another vulnerbility been found on 
index.baidu.com.



Description of Vulnerability:

-----------------------------

There is a XSS vulnerability exist on baidu.com which found by a Internet user.





Impact:

-------

No more repeat about such types of vulnerabilities



Mitigating factors:

-------------------



Proof of concept:

-----------------

Take a look at the attached file.



Timeline:

---------

2010-02-08 - Baidu notified







      

Attachment: baidu-xss.JPG
Description: JPEG image

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/