Security researcher Azat Harutyunyan, has submitted on 27/05/2008 a cross-site-scripting (XSS) vulnerability affecting shop.usps.com, which at the time of submission ranked 323 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 08/06/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 27/05/2008 |
Date published: 08/06/2008 |
Fixed? Mail us! | Status: UNFIXED |
URL: http://shop.usps.com/webapp/wcs/stores/servlet/CatalogSearchResultView?storeId=10001&catalogId=10152 &langId=-1&pageSize=8&beginIndex=0&sType=AdvancedSearch&resultType=2&searchTerm=%22%3E%3Cscript%3Eal ert%281%29%3C%2Fscript%3E&searchTermScope=4 |
Click here to view the mirror
|
|
|