Apple.com XSS attack
i.imgur.com
i.imgur.com
http://www.apple.com/itunes/affiliates/download/?artistName=<iframe+id%3D"frame"+src%3D"http://www.microsoft.com/"+style%3D"width:+600px;+height:+400px;"></iframe>&thumbnailUrl=http://www.straitstimes.com/STI/STIMEDIA/image/20090501/windows7-microsoft.jpg&itmsUrl=http://www.microsoft.com&albumName=Better+Operating+SystemFree iTunes until you get caught. Chances are Apple would be able to track who downloaded what onto what Apple devices. I'm sure retribution would be swift and thorough.
In my opinion that does count as an XSS attack, though it perhaps does not use the traditional techniques. (This for those who have said that this is actually not an XSS attack.)
http://www.apple.com/itunes/affiliates/download/?artistName=...
It doesn't allows any kind of <script> tag, so yeah, it's fun and a bit insecure (may be used for phishing?? dunno), but it's not the worst at all.
http://www.apple.com/itunes/affiliates/download/?artistName=...
http://www.apple.com/itunes/affiliates/download/?artistName=...
http://www.apple.com/itunes/affiliates/download/?artistName=...
I'm sure that when Apple finds this they'll close the gap pretty fast though.
Seems like it doesn't work in latest WebKit?