<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>XSS Vulnerabilities</title><link>http://blogger.xs4all.nl/gjvm/category/32941.aspx</link><description>XSS Vulnerabilities</description><managingEditor>Godert Jan van Manen</managingEditor><dc:language>nl-NL</dc:language><generator>.Text Version 0.95.2004.102</generator><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.arcenenvelden.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415797.aspx</link><pubDate>Tue, 30 Sep 2008 16:55:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415797.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415797.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415797.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415797.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415797.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/arcenenvelden.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415797.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.apeldoorn.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415796.aspx</link><pubDate>Tue, 30 Sep 2008 16:51:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415796.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415796.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415796.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415796.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415796.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/apeldoorn.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415796.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.noord.amsterdam.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415795.aspx</link><pubDate>Tue, 30 Sep 2008 16:46:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415795.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415795.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415795.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415795.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415795.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/noordamsterdam.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415795.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.amstelveen.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415793.aspx</link><pubDate>Tue, 30 Sep 2008 16:41:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415793.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415793.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415793.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415793.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415793.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/amstelveen.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415793.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.alphen-chaam.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415791.aspx</link><pubDate>Tue, 30 Sep 2008 16:33:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415791.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415791.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415791.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415791.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415791.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/alphenchaam.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415791.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.alkmaar.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415789.aspx</link><pubDate>Tue, 30 Sep 2008 16:16:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415789.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415789.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415789.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415789.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415789.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/alkmaar.jpg"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415789.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.aalsmeer.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415787.aspx</link><pubDate>Tue, 30 Sep 2008 16:07:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415787.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415787.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415787.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415787.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415787.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/aalsmeer.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Updated&lt;/STRONG&gt;: 30-09-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine doesn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor has been notified of the vulnerability. No response yet!&lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415787.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.trouw.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415773.aspx</link><pubDate>Tue, 30 Sep 2008 14:21:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415773.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415773.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415773.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415773.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415773.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/trouw.jpg"&gt; &lt;/P&gt;&lt;BR&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine didn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This vulnerability has been promptly fixed by Trouw&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt; &lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415773.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Godert Jan van Manen</dc:creator><title>Cross-site scripting (XSS) vulnerability in www.ah.nl</title><link>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415772.aspx</link><pubDate>Tue, 30 Sep 2008 14:17:00 GMT</pubDate><guid>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415772.aspx</guid><wfw:comment>http://blogger.xs4all.nl/gjvm/comments/415772.aspx</wfw:comment><comments>http://blogger.xs4all.nl/gjvm/archive/2008/09/30/415772.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blogger.xs4all.nl/gjvm/comments/commentRss/415772.aspx</wfw:commentRss><trackback:ping>http://blogger.xs4all.nl/gjvm/services/trackbacks/415772.aspx</trackback:ping><description>&lt;P&gt;&lt;IMG src="http://www.van-manen.info/ah.jpg"&gt; &lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Release date:&lt;/STRONG&gt; 07-05-2008&lt;BR&gt;&lt;STRONG&gt;Found by:&lt;/STRONG&gt; Godert Jan van Manen&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;The Search engine and shopping card didn't sanitize any search results. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This vulnerability has been promptly fixed by Albert Heijn&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt; &lt;/P&gt;&lt;img src ="http://blogger.xs4all.nl/gjvm/aggbug/415772.aspx" width = "1" height = "1" /&gt;</description></item></channel></rss>
