[Full-disclosure] StumbleUpon XSS (fixed)



Hi all,

I found an XSS issue in StumbleUpon, which has been fixed. If you're
interested in what the problem was, look here: http://skypher.com/

What I found most interesting about this case is that there were only 40
minutes between the acknowledgement of receipt of my email about the issue
and their fix being online. In my experience that is really, really fast!

Cheers,

SkyLined

--------------------------------------------------------------------------------------------------------
Berend-Jan Wever <berendjanwever@xxxxxxxxx> http://skypher.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Re: [Full-disclosure] Gmail 0day
    ... Your Gmail session is hijacked (i.e.: via the XSS PoC posted on FD) ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • =?KOI8-R?Q?Re:_[Full-disclosure]_XSS_at_msn.com_=C9_cisco.com?=
    ... It looks like I have:) See my next message "XSS at nsa.gov" or just visit ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Gmail 0day
    ... Blackhat SEO XSS ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ... Full-Disclosure - We believe in xss. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Month of ActiveX Bug
    ... [Full-disclosure] Month of ActiveX Bug ... Even XSS bugs in open source perl webmail apps. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] The Next Super JavaScript Malware - the web has crashed
    ... xssed.com, which goal is to organize the public XSS vulnerabilities, make ... and first of all to spread education about XSS ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)