
Reflected XSS vulnerability disclosure for Yahoo YUI library, with proof-of-concept exploits across multiple PHP endpoints for security testing and awareness.
Since Yahoo is no longer updating the project (per this announcement: https://yahooeng.tumblr.com/post/96098168666/important-announcement-regarding-yui), I've decided to disclose the vulnerabilities here:
The application has a lot of reflected XSS vulnerabilities in pretty much most files. A sample of the vulnerable files along with the exploit can be found here: