Stored XSS Vulnerability in Amazon (or How to hack Amazon with a book)
drwetter.eu
drwetter.eu
Actually a useful link to have; I've had some difficulty convincing people in the past that this sort of injection is a big deal and that's a convenient, harmless way to prove the point.
But writing a book as an attack vector is certainly epic.
http://www.amazon.com/XSS-Attacks-Scripting-Exploits-Defense...
I'm not seeing this vulnerability now via Mac FireFox 3.6.12 or Safari.