<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Democracy 2.0.1 HTML Injection Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/comment-page-1#comment-6503</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Fri, 18 Jan 2008 16:46:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/#comment-6503</guid>
		<description>Aaron, you asked for it :):
Try (in IE7)

http://www.problogger.net/&#039;style=xss:expression(alert(document.cookie));//

You may have to force close your IE afterwards though, so be prepared :)

Note: you may need to replace the single quote manually, as a direct copy and paste may not work.

</description>
		<content:encoded><![CDATA[<p>Aaron, you asked for it :):<br />
Try (in IE7)</p>
<p><a href="http://www.problogger.net/" rel="nofollow">http://www.problogger.net/</a>&#8217;style=xss:expression(alert(document.cookie));//</p>
<p>You may have to force close your IE afterwards though, so be prepared :)</p>
<p>Note: you may need to replace the single quote manually, as a direct copy and paste may not work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/comment-page-1#comment-6500</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:58:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/#comment-6500</guid>
		<description>I released the original exploit a year and a half ago, so hi, welcome to the fraternity of Democracy exploit finders. We&#039;re a small and humble bunch. ;-)

I can&#039;t get this to work though. Maybe I&#039;m missing something. My team has tested on all major browsers and on Macs and PCs. Can you elaborate on the trick here? Or contact me privately and we can look at some specific cases.</description>
		<content:encoded><![CDATA[<p>I released the original exploit a year and a half ago, so hi, welcome to the fraternity of Democracy exploit finders. We&#8217;re a small and humble bunch. ;-)</p>
<p>I can&#8217;t get this to work though. Maybe I&#8217;m missing something. My team has tested on all major browsers and on Macs and PCs. Can you elaborate on the trick here? Or contact me privately and we can look at some specific cases.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BOK</title>
		<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/comment-page-1#comment-6471</link>
		<dc:creator>BOK</dc:creator>
		<pubDate>Thu, 17 Jan 2008 11:54:36 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/#comment-6471</guid>
		<description>Plugin removed after minor issues. Searching for solutions showed that this plugin has a long reputation of weird issues and author&#039;s support is minor...
Taken the possible insecurity-issue (though fixed here) I came to my descision.</description>
		<content:encoded><![CDATA[<p>Plugin removed after minor issues. Searching for solutions showed that this plugin has a long reputation of weird issues and author&#8217;s support is minor&#8230;<br />
Taken the possible insecurity-issue (though fixed here) I came to my descision.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/comment-page-1#comment-6451</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Wed, 16 Jan 2008 22:25:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/#comment-6451</guid>
		<description>dre, I found it on BlogSec yes.</description>
		<content:encoded><![CDATA[<p>dre, I found it on BlogSec yes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dre</title>
		<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/comment-page-1#comment-6448</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Wed, 16 Jan 2008 16:10:12 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/#comment-6448</guid>
		<description>don&#039;t you run the Democracy plugin on this blog?  did you find this from dynamically testing or did you find it in the code?</description>
		<content:encoded><![CDATA[<p>don&#8217;t you run the Democracy plugin on this blog?  did you find this from dynamically testing or did you find it in the code?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BOK &#187; Blog Archive &#187; QotD - 5</title>
		<link>http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/comment-page-1#comment-6446</link>
		<dc:creator>BOK &#187; Blog Archive &#187; QotD - 5</dc:creator>
		<pubDate>Wed, 16 Jan 2008 13:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/democracy-201-html-injection-vulnerability/#comment-6446</guid>
		<description>[...] installed a polling plugin (and fixed it), so let&#8217;s make this a democratic process!     Would you pay $20 / €18 for the extra iPod [...]</description>
		<content:encoded><![CDATA[<p>[...] installed a polling plugin (and fixed it), so let&#8217;s make this a democratic process!     Would you pay $20 / €18 for the extra iPod [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

