For the site search injection that The_Cynic mentioned, it actually requires a site that will redisplay the text you gave it on its website and not filter out the < and > symbols. So far I've not found a site with that security vulernability other than quantcast, which was already mentioned early in this thread.
|