JS embedding @ yahoo.com
From: Alan McCaig (alanmccaig@yahoo.co.uk)Date: 03/28/02
- Previous message: Klaus Ripke: "vuln in wwwisis: remote command execution and get files"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 28 Mar 2002 11:48:25 -0000 From: Alan McCaig <alanmccaig@yahoo.co.uk> To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is)
Any user can embed JavaScript into there yahoo
profiles. When the user selects to change his picture
then selects point to a photo on the Web. They can
then embed javascript on the end of the url. An
example of this can be viewed here
http://uk.profiles.yahoo.com/embeddedjs
This has been active for a while now and yahoo have
still took no action in fixing it.
- Previous message: Klaus Ripke: "vuln in wwwisis: remote command execution and get files"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|