Stephan Esser just posted about a potentially universal XSS in Adobe's PDF plugin first mentioned here. All it requires is appending "#something=javascript:<insert script here>;" to the end of the link and Adobe PDF will happily execute the JavaScript.
You should probably disable Adobe's PDF plugin in the meantime. If you don't think XSS attacks are particularly interesting, check out what you can do with XSSProxy.
Barry Irwin

singe: Awesome breakdown from the reigning Web App Scanner queens NTObjectives on why their scanner kicked the other's asses http://is.gd/9e0GZ
extern blog SensePost; : Decrypting Symantec BackupExec passwords
0 Trackbacks