Has anyone seen this announcement?
It is talking about a new login... I think this could be XSS exploitable...
url is
Heads Up: New Login Screen | Forum | Gaia Online

url is
Heads Up: New Login Screen | Forum | Gaia Online


Gaia says: wrote:But remember: beautiful as this new screen is, you should always check your address bar before logging in. If it doesn't say "http://www.gaiaonline.com/," don't put in your password! We know it's tempting to trust addresses like "http://gaiahack.virus.biz.ru.exe," but fake login screens are a common phishing tactic, so stay frosty out there, soldiers.

The_Theomorphic_Librarian wrote:They're merely trying to act as if they're doing anything to prevent it, but fact is, there's little they can do.
People are probably being scammed as of this very moment :/
Nova wrote:>XSSexploitablevulnerable.
The only difference in the login screen is that it's only a log in with nothing else; nowhere did they add a place that outputs your input, let alone one that isn't filtered.
The_Theomorphic_Librarian wrote:This reminds me of the days of SQL Injection 'n messing about with Javascript...
You haven't been on HTS, now have you?