PayPal.com suffered from a cross site scripting vulnerability.
6774aed58d76defe6afe169dfc07e49e4df024c41e35159681c6dcf99fb6f591
Paypal is affected by an XSS vulnerability where it fails to validate
input for the following url:
https://www.paypal.com/xclick/business=
One can add arbitrary javascript with no need for any filter evasion.
https://www.paypal.com/xclick/business=<script> alert("xss"); </script>
As far as I know only the above url is affected. All of the usual XSS
attacks will work with this.
Cheers.