Norman XSS

6/15/2009

Juha-Matti Laurio

http://linuxbox.org/pipermail/funsec/2009-June/021134.html



Norman has an XSS vulnerability. You can see an archive of it and any status update regarding it being fixed at XSSed.com.

XSS URL provided: http://www.norman.com/site_search/en?searchString%3Autf8%3Austring="><iframe src=index.htm


main page ATTRITION feedback