+*-,+*-,+*-,+*-,+*-,+*-,++*-,/+*-,=+*-,+*-,+*-,+*-,www.cnn.com+*-,+*-,/+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,http://www.cnn.com/+*-,200+*-,OK+*-,255.255.255.255+*-,4294967295+*-,%FF%FF%FF%FF+*-,0377.0377.0377.0377+*-,42+*-,#+*-,web app security+*-,*+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,+*-,Enumeration+*-,Examine Source Code+*-,Hostnames+*-,+*-,Inject this string, and in most cases where a script is vulnerable with no special XSS vector requirements the word "XSS" will pop up.+*-,+*-,%3cscript%3ealert('xss')%3c/script%3e+*-,Host: www.cnn.com User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0 Accept-Encoding: gzip Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Connection: keep-alive +*-,+*-,Date: Thu, 16 Nov 2006 17:55:32 GMT Server: Apache Vary: Accept-Encoding,User-Agent Content-Encoding: gzip Cache-Control: max-age=60, private Expires: Thu, 16 Nov 2006 17:56:25 GMT Content-Length: 19667 Content-Type: text/html Keep-Alive: timeout=5, max=1024 Connection: Keep-Alive +*-,CNN.com - Breaking News, U.S., World, Weather, Entertainment & Video News Click here to skip to main content.
UPDATED: 12:54 p.m. EST, November 16, 2006
Make CNN Your Home Page
Pelosi wins then loses
From left: Pelosi, Murtha and Hoyer

Pelosi wins then loses

California Rep. Nancy Pelosi will be the first woman speaker of the House, after winning a unanimous vote among her Democrat colleagues. But Pelosi saw John Murtha -- her pick for majority leader -- lose out to Steny Hoyer in the race to become the powerful deputy.

FULL STORY

• Audio Slide Show: What's next for Democrats

icon_video.gifhdr_watch_vid.gif
txt_most_pop_blue_wt.giftxt_best_video_grey.gif
ExpandCollapse
1. No order in this court (:44)
No order in this court

From affiliate WYTV: A family beats up an accused murderer in an Ohio courtroom (November 16)

ExpandCollapse
2. Smith wins 'Dancing with the Stars' ... (2:41)
Smith wins 'Dancing with the Stars'

Emmitt Smith and his partner Cheryl Burke are the winners of ABC's 'Dancing with the Stars.' (November 16)

ExpandCollapse
3. Sexiest politician (2:28)
Sexiest politician

CNN's Jeanne Moos hit the street to get nominations for the sexiest politician alive. (November 15)

ExpandCollapse
4. Hamas trains new army (3:08)
Hamas trains new army

CNN's Ben Wedeman visits a training camp for a new Hamas fighting force. (November 15)

txt_most_pop_grey.giftxt_best_video_blue_wt.gif
ExpandCollapse
Neanderthal DNA unlocked (3:35)
Neanderthal DNA unlocked

Scientists in Germany say they've cracked the Neanderthal genetic code. ITN's Tom Clarke reports. (Novembe ...

ExpandCollapse
Couple can't smoke in home (1:14)
Couple can't smoke in home

A Colorado couple is no longer allowed to smoke in their own house. KDVR's Heidi Hemmat reports. (November 16)

ExpandCollapse
Michael Jackson back on stage (1:24)
Michael Jackson back on stage

Michael Jackson took the stage at the World Music Awards in London. CNN's Mallika Kapur reports. (November 16)

ExpandCollapse
Waived consent controversy (3:53)
Waived consent controversy

CNN's Dr. Sanjay Gupta reports on a rarely-used clinical testing rule for emergencies. (November 16)

ExpandCollapse
Now In The News (Updated: 12:19 p.m. ET)
Now in the News

Your quick news update

advertisement.gif
CNN Pipeline: Live and commercial free video

txt_live_blue_wt.giftxt_what_is_pipe_grey.gif
ExpandCollapse
Live House Dems Select Leadership
CNN Pipeline stream image

House Democrats speak to reporters after selecting their new leadership team.

ExpandCollapse
Live Senate Debate
CNN Pipeline stream image

Senators meet for a lame-duck session before Democrats take power in January.

ExpandCollapse
Live UN General Assembly
CNN Pipeline stream image

Members of the United Nations meet in New York for the General Assembly.

ExpandCollapse
Live Indiana Chemical Leak
CNN Pipeline stream image

Interstate 65 near Lowell, IN, is closed while authorities neutralize a chemical leak.

live.giftxt_what_is_pipe_blue_wt.gif
Live Video Move beyond free video
DOW
12,283.72
+ 32.01
NAS
2,444.12
+ 1.37
S&P
1,400.37
+ 3.80
Enter Symbol: or Symbol Look-up
Updated: 12:35 p.m. ET, Nov 16
sponsored by:
RATING THE TUNES
The all-TIME 100 albumsTime.com: The all-TIME 100 albums
See if you agree with TIME's list of the greatest and most influential records ever
US
BREAKING ONION NEWS
Satire: Laid-off autoworker optimisticSatire: Laid-off autoworker optimistic
Former Ford employee decides to start his own car company, reports The Onionexternal link
US WORLD
TECHNOLOGY ENTERTAINMENT
POLITICS LAW
HEALTH SCIENCE & SPACE
TRAVEL EDUCATION
SPORTS • Ten NFL guys who need to get lost ... now
• Ranking the 10 best Michigan-Ohio St. duels
BUSINESS • Gas drop puts inflation on the ropes
• Wrecking-ball bait: 5 teardowns
Nicole Simpson's family reacts to O.J. Simpson's bone-chilling new book and upcoming interview. Should he profit from her death?
Full Schedule
PEP TALK
Fighting funk and fatigue
Fighting�funk and fatigueHow to put the bounce back in your step when your energy is zapped
FRIENDS, FAMILY AND FOOD
Time to give thanks
Time to give thanksWho and what are you grateful for this Thanksgiving? And what's on your menu?
OH DEER!
In search of doe
In search of doeA deer breaks into a bank and leaves behind all the signs of a crime
quickvote
Who should take the lead in climate change initiatives?
or View Results
+*-,notes go here+*-,##########################################+*-,Cross Site Scripting (XSS) attacks an application's users instead of the application itself. It is caused by the failure of an application to validate output before returning it to the client's web browser. Allows attacker-controlled HTML to be inserted into the vulnerable page. Attackers may use this technique to steal valuable information (usernames, passwords, billing info, cookie data etc.) from unsuspecting site users.+*-,Insert scripting elements into all application input parameters: Did the application allow the scripts? If yes, were the scripts embedded in the app response and executed? If no, what was the response?+*-,Your results here+*-,www.yahoo.com+*-,