| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <eb0de0f1003261246u7283c5aetb15c87ae310c3ba5@mail.gmail.com>
Date: Fri, 26 Mar 2010 15:46:09 -0400
From: Wesley Kerfoot <wjak56@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Paypal XSS Vulnerability
Paypal is affected by an XSS vulnerability where it fails to validate
input for the following url:
https://www.paypal.com/xclick/business=
One can add arbitrary javascript with no need for any filter evasion.
https://www.paypal.com/xclick/business=<script> alert("xss"); </script>
As far as I know only the above url is affected. All of the usual XSS
attacks will work with this.
Cheers.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/