What is the process for submitting a Zero Day vulnerability?
Hey there guys,
I've found a Zero Day vulnerability (Just URI XSS) though it is affecting anywhere in the range of ~6M websites (according to Google).
I was wondering what the process I should follow is. (Report to vendor, wait for them to update software then disclose?)
I also was wondering the legality of this, am I likely to get into any kind of trouble here?
~JungleCats