Wednesday, January 18, 2012

#www.universalmusic.com HTML/XSS Insertion

Universalmusic.com allow insertion of html and javascript tags a proof of concept here: http://www.universalmusic.com/artists?filter0=xss><ifrane><h1>XSSTORM


Wednesday, November 23, 2011

#www.me.gob.ve XSS BUG

#www.me.gob.ve allow insertion of javascript code in the search field it can be exploited here #www.me.gob.ve/busqueda.php?texto="XSS/HTML"

#intranet.ivic.gob.ve XSS/HTML injection

#intranet.ivic.gob.ve HTML/XSS code insertion non stored
poc: https://intranet.ivic.gob.ve/index.php?error="XSS/HTML"

#gobiernoenlinea.gob.ve XSS BUG

#gobiernoenlinea.gob.ve Search engine allow html and javascript insertion.



Wednesday, November 16, 2011

#Linkedin.com Multiple XSS "Edit Profile"

Linkedin.com allow Cross site scripting code insertion in "Edit Profile" secction. XSS Stored
video

Thursday, November 10, 2011

#hilton.co.uk XSS Vuln

#hilton.co.uk search engine its vulnerable to XSS attacks.

#secure.diigo.com XSS

XSS and HTML injection #secure.diigo.com/sign-up?referInfo=#XSS a proof of concept here