Evan Ricafort, managed to run a Javascript popup boxes in the official website of National Geographic (nationalgeographic.com) , Sony’s playstation (us.playstation.com) and Barack Obama (barackobama.com.)
Ricafort writes message in the alert boxes, “XSS by Evan_Popup.”
The Cross-site scripting vulnerability is already reported, the researcher told us on pinoyhacknews.