I stumbled upon §øüLêÿ’s blog and found this entry titled XSS in youtube.com!!! from december 2006. Try the following link and you’ll get a JavaScript alert on YouTube.com. As I am not a professional, I don’t know if it’s a real XSS vulnerability in YouTube’s website. Maybe you can do even more, I don’t know. And maybe it’s nothing and doesn’t need to be fixed.
Youtube XSS
(opens in a new window, JavaScript needs to be enabled)
Thats what you get:
One response to “Youtube XSS vulnerability?”
[…] saw it on Cordoba quoting […]