Re: [FD] Regarding how can I request a CVE number?

2015-03-18 Thread James Hooker
Hi XZ, I managed to get a number of CVEs last year, but towards the end of the year they simply stopped replying, so I've given up. Whether they stopped replying due to work load, or whether my submissions were not up to their requirements I'm not sure. If you find out any more, I'd be interested

Re: [FD] XSS (in 20 chars) in Microsoft IIS 7.5 error message

2014-12-03 Thread James Hooker
You could skip the schema on any includes, and just use '//'. That will then use the schema provided in the original URL. That will save you 4 characters at least. You can also skip most quotes in tags - that will save you a few more characters. Link shortening services might also be of use, howeve