信息来源:Zuso Security
As you know, Yahoo is a well-known website in the world. We found that there are some XSS vulnerabilities by encoding the HTML code twice in the URI. We have notified the vendor on 4.24 already.
POC:
Link
Enter any username and password you like, and then submit it, you'll see what happen.
The original advisory is located at http://www.zuso.org.tw/index.php?option=com_content&task=view&id=32&Itemid=1
Zuso Security is a group which is focus on web-based security in Taiwan.
Zuso Security -
vuln_AT_zuso.org.tw (vuln info only)
http://www.zuso.org.tw/
irc.zuso.org.tw #zuso (SSL tunnel: port 994)