Nothing new here though, I

Nothing new here though, I don't know how this is any different than any other `stored` XSS vulnerability.

E.g. You can inject syslog messages with XSS exploit and when admin looks at them within a browser you get credentials (if not properly sanitized). This is no rocket science, I see this everyday :-(

Reply

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.