Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

Baidu XSS Zero Day

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


beatyouman at ymail

Feb 9, 2010, 1:54 AM

Post #1 of 1 (285 views)
Permalink
Baidu XSS Zero Day

Baidu.com is the bigest search engineen provider in China. After
been hacked by Iran Cyberarmy. There is another vulnerbility been found on index.baidu.com.



Description of Vulnerability:

-----------------------------

There is a XSS vulnerability exist on baidu.com which found by a Internet user.





Impact:

-------

No more repeat about such types of vulnerabilities



Mitigating factors:

-------------------



Proof of concept:

-----------------

Take a look at the attached file.



Timeline:

---------

2010-02-08 - Baidu notified
Attachments: baidu-xss.JPG (79.1 KB)

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.