Re: Yahoo Messenger 7.0.0.438 Crash Tested
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
It seems that any number of alternative strings will work as well:
example:
"msg:_________________________________________iframe onload=$InlineAction()>:)" without quotes works as well.
[, -, ^, {, [alt-0160]'s all seem to work as well
Is there a cross scripting vulnerability as well? Inserting script commands brings up an odd Script Error screen and a file name.