OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: google xss

From: Andy Meyers (andy.meyershushmail.com)
Date: Sun Apr 09 2006 - 18:50:27 CDT


My BlackICE stops this from XSS from happening, however changing the URL
from a .ae domain to a .com and leaving the rest in tact, I am then
prompted.

http://www.google.com/search?hl=ar&q=<script>alert("1")</script>&meta=

Ashes

-----Original Message-----
From: almfnodgawab.com [mailto:almfnodgawab.com]
Sent: Tuesday, April 04, 2006 2:35 PM
To: bugtraqsecurityfocus.com
Subject: google xss

http://www.google.ae/search?hl=ar&q=<script>alert("1")</script>&meta=