Just a notice, as this will probably be fixed in a short amount of time - I can add persistent XSS to the group page. I first noticed this yesterday when I was fooling around with URL XSS attempts, and then followed up with form injections. The hole is in the group "url" field, and is easily exploited, although I haven't tested for form length (I assume there is no limitation, if so then a simple link to an external file is sufficient to get around this). This was again noticed by .Mario (of sla.ckers and gnucitizen.org) sometime today during his tests on the site, and he has a PoC group page up for disclosure in case anyone doesn't understand what I mean. There are still more holes in the site, but persistent XSS is always fun ;) Luckily for us, ning actually respond rather quickly to disclosure, and as such we should be able to get this web portal locked down and secure within the next week or so - they're getting free security tips, and we're getting a free community portal. Hmm, can we write apps for ning? There's plenty of stuff I would like to add to this system.
Post your XSS finds for ning.com here, and I'll forward them onto the ning security team. Don't forget you can use subdomains too if they're applicable. If for SOME reason an SQL hole is lying around, I'd prefer you disclose it to ning yourself - leaving it out in the open on a public forum isn't desirable :)
Edit: I've used this hole to hack our group page - it looks pretty now ;) (no javascript involved, I'm not hacking you!)
--------------------------------
User submitted XSS List:
--------------------------------
Blog Post by
Wildcat on multiple XSS vulns & their status.
Group Page by
Sam Aldis that uses Javascript CSRF to submit a message form to PDP.
PoC by
Sam Aldis - reflective XSS.
Post by Fragge.