Re: Yahoo Messenger 7.0.0.438 Crash Tested

[email protected]
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
It seems that any number of alternative strings will work as well:
example:
"msg:_________________________________________iframe onload=$InlineAction()>:)" without quotes works as well.

[, -, ^, {, [alt-0160]'s all seem to work as well

Is there a cross scripting vulnerability as well?  Inserting script commands brings up an odd Script Error screen and a file name.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.