Hacker News new | ask | show | jobs
by johnsonjo 3755 days ago
Even though you did manage to get that far. It doesn't seem that you can actually make it persist or anything like that on his site so it is probably about as useful of an XSS as typing directly into the console on your browser.
2 comments

Reflected XSS is still a big security problem.

http://www.acunetix.com/blog/articles/non-persistent-xss/

Yea, I wouldn't have posted it here if it was more severe. Just some fun script injection.