Security researcher C1c4Tr1Z, has submitted on 27/07/2008 a cross-site-scripting (XSS) vulnerability affecting sso.americanexpress.com, which at the time of submission ranked 646 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 28/07/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 27/07/2008 |
Date published: 28/07/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: C1c4Tr1Z |
Domain: sso.americanexpress.com |
Category: XSS |
Pagerank: 646 |
URL: https://sso.americanexpress.com/SSO/request?request_type=un_createid&ssobrand=&ssolang=en_US&REALMOI D=06-3dcadafa-92e6-0028-0000-151f0000151f&SSOURL=%22%0B+onmouseover=alert(/XSS/)+foo=%22&VALUE=abc |
Click here to view the mirror
|
|
|