So this is a vulnerability on Disqus. Not so much on Etherscan. Any site which uses the Disqus comment box might be vulnerable. The fact that the hacker just do a JavaScript alert message instead of running a silent script probably indicate that they just want to prove a point and not out to do serious damage. Just my 2 cents
Posted using Partiko Android