You misstyped your syntax... it should be:
<script>alert('secured!')</script>
But yes you are right.
----- Original Message -----
From: "Logan5" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, February 06, 2004 3:06 PM
Subject: RE: [Full-Disclosure] home land tracker software
> LOL
>
> The NAMECHECK dialog is succeptable to XSS. Enter the following into
> any of the fields:
>
> <script>alert('secured!')</alert>
>
> -L5
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html