XSS at Cnn.com – again
October 16th, 2007 by Juha-Matti, Filed under: Commentary, Corporate Security, Web
In August we saw a cross-domain injection type XSS report from CLPWN related to Cnn.com.
The target was Search.cnn.com.
This week, Xssed.com reports about the new issue.
According to the ‘Additional information’ field of the report
XSS in the “Get your local weather and news” form
No exact string was given.
Additionally, the Xssed database lists the issue as Unfixed.
-
http://kaneda.bohater.net Kanedaa
-
http://blog.fukami.io fukami
-
Sali
-
http://clpwn.com clpwn
-
MoshBat



