TITLE: Yoono Desktop Application Persistent XSS vendor: Yoono Version: 1.8.16 Impact: Persistent XSS Software Link: available in yoono site Author: r007k17-w Email: n4gb07@gmail.com Twitter: http://twitter.com/#!/r007k17w My blog: http://shadowrootkit.wordpress.com/ ------------------------------------------------------------------------------------------------------------------------------------------- DEMO: 1.From yonoo Apps Login with any account(say google). 2.Online friend list is opened 3.Click 'friends' link just below the status field. 4.Pop up window 'Add friends' is seen. 5.Input random email-id,eg: qwerty@xyz.com and Create a group by selecting field.(drop down) 6.Now in the 'create' field POST DATA:">