Page 1 of 1

XSS @ CNN liveTV

Posted: Tue Mar 06, 2012 4:01 pm
by satyrias
I have been trying to get the CNN liveTV after enabling NoScript.

I used to watch the CNN live TV, after entering the password of my local cable service, which is Comcast. I think the problem is this Cross site restriction. But, I don't know how to write the regular expression to enter in the exception.

Would someone help me with it?

Thanks

Re: XSS @ CNN liveTV

Posted: Tue Mar 06, 2012 4:30 pm
by therube
Does the Error Console show anything relevant?

Re: XSS @ CNN liveTV

Posted: Tue Mar 06, 2012 4:55 pm
by satyrias
Yes, it showed XSS with a mark. Right now I can't reproduce it to say exactly what was it after I made several changes..

This is the site I am talking about:
http://www.cnn.com/video/?_=105143#/vid ... cvpstream1

Re: XSS @ CNN liveTV

Posted: Wed Mar 07, 2012 1:51 am
by GµårÐïåñ
Unless you want to exempt the whole site, which is a bad idea, then you need give us the actual XSS notice it gives so we can give you something specific and useful. Next time you get the XSS message, go to Error Console, copy it and paste it here. Your link produces no error for us, so it must be something on your end or a false hit unless you can provide the needed debug info to see what gives.