<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2680014473523685840</id><updated>2011-04-21T21:18:14.826-07:00</updated><title type='text'>TestBlog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://xssvulnerabilities.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2680014473523685840/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://xssvulnerabilities.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Christian Matthies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2680014473523685840.post-8404305814176348333</id><published>2007-03-03T03:00:00.000-08:00</published><updated>2007-03-03T03:02:01.840-08:00</updated><title type='text'>Google</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_Xuy5-EZy_Jw/RelVnSmX0pI/AAAAAAAAABQ/XM9iXUaokmg/s1600-h/logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_Xuy5-EZy_Jw/RelVnSmX0pI/AAAAAAAAABQ/XM9iXUaokmg/s320/logo.png" alt="" id="BLOGGER_PHOTO_ID_5037651791686652562" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;"&gt;'&gt;&lt;SCRIPT&gt;alert(4)&lt;/SCRIPT&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2680014473523685840-8404305814176348333?l=xssvulnerabilities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xssvulnerabilities.blogspot.com/feeds/8404305814176348333/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2680014473523685840&amp;postID=8404305814176348333' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2680014473523685840/posts/default/8404305814176348333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2680014473523685840/posts/default/8404305814176348333'/><link rel='alternate' type='text/html' href='http://xssvulnerabilities.blogspot.com/2007/03/google.html' title='Google'/><author><name>Christian Matthies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_Xuy5-EZy_Jw/RelVnSmX0pI/AAAAAAAAABQ/XM9iXUaokmg/s72-c/logo.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2680014473523685840.post-6389002631261416929</id><published>2007-01-01T02:04:00.000-08:00</published><updated>2007-04-29T08:46:54.423-07:00</updated><title type='text'>XSS vulnerabilities</title><content type='html'>I was quite impressend when I discovered this security hole in the sidebar plugin. It should be clear that all kind of feeds are potentially insecure but obviously the Google guys forgot about that.&lt;br /&gt;&lt;br /&gt;I reported the bug a couple of hours ago, we'll see how much time they need to fix it and whether I'll get a reply ;-)&lt;div class="blogger-post-footer"&gt;"&gt;'&gt;&lt;SCRIPT&gt;alert(4)&lt;/SCRIPT&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2680014473523685840-6389002631261416929?l=xssvulnerabilities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xssvulnerabilities.blogspot.com/feeds/6389002631261416929/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2680014473523685840&amp;postID=6389002631261416929' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2680014473523685840/posts/default/6389002631261416929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2680014473523685840/posts/default/6389002631261416929'/><link rel='alternate' type='text/html' href='http://xssvulnerabilities.blogspot.com/2007/01/test-entry.html' title='XSS vulnerabilities'/><author><name>Christian Matthies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
