Friday, March 16, 2007

Cisco.com XSS




Wow!!! Amazing, great job trev. Cisco.com vulnerable to XSS. Mad props to trev. The following is the code. Yall can use WebScarab to proxy the connection to try this XSS!! Below is the code. Once again, nice one trev

http://tools.cisco.com/newsroom/contactSearch/jsp/prSearch.jsp&mode=nameSearch&nameSearch=--%3E%3Cscript%3Ealert(%22xss%22)%3C/script%3E



mode:

nameSearch: