lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAO3sRvkn0d0VRTEa+QUbO+vLS1FVS6h9O5Jre-7mc4mz8LERmw@mail.gmail.com>
Date: Tue, 1 Nov 2011 10:12:32 +0530
From: asish agarwalla <asishagarwalla@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Adobe Web-Site Persistence XSS
Title:
======
Adobe Web-Site Persistence XSS
Status:
========
Unpatched
Details:
========
1. Signin to adobe.com
2. Go to My information
3. Change Screen Name to
>'><script>alert("xss"); or '><script>alert("xss");
4. Go to My adobe
@Asish (asishagarwalla@...il.com)
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/