WHID 2006-35: Yahoo mail XSS in CSS expression keyword

Share/Save

Yahoo mail does not filter properly the CSS "expression" keyword when it includes a comment that is encoded.

Additional information:

Incident Outcome: