Wednesday, April 26, 2006

Blogger.com, Monster.com XSS


Check out the advanced search with keyword
script alert(document.cookie); script

for monster.com[indian website, not tested in others] and for blogger, try posting with the text as shown above.

Voila!!!
The paranthesis have been removed by blogger.com as it doesnot permit html tags

Not sure if one can exploit the blogger.com bug.
Voila!!!
Anyway Xss is not such a big issue or is it?:-)...

$um$id