Hi,

Has Mitt Romney had anything to say yet in his campaign about
cyber-security?  I'm asking because I just found a cross-site scripting
error at the Romney campaign Web site.  Here's a quick and dirty demo of the
problem:

   http://tinyurl.com/3dowmd

This bug can be used by outsiders to inject their own "custom" content at
the Romney Web site.

I wonder if the site has more interesting bugs such as an SQL injection
error in a back-end database.....

Richard M. Smith


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Reply via email to