Sunday, September 09, 2007

IE home page URL resulting in XSS?

I am not able to phrase the title of this entry correctly, but this is what I have found....

Copy the following link location and set it as your homepage in IE 7.

COPY THIS LINK

When you open a new window in IE, it echoes your home page url in the window which results into something similar to XSS.

I am trying to find a way to exploit this (like automatically setting homepage and adding some javascript), but if you already have an idea, please let me know.