PlanetCreator has reported another critical XSS Vulnerability on classified listings site Ads.com.mm
Cross Site Scripting is a client-side attack where an attacker can craft a malicious link, containing script- code which is then executed within the victim’s browser when the target site vulnerable to and injected with XSS is viewed. The script-code can be any language supported by the browser but mostly HTML and Javascript is used along with embedded Flash, Java or ActiveX.
We hope that your security staff will look into this issue and fix it as soon as possible.