Security researcher skathgh420, has submitted on 16/09/2008 a cross-site-scripting (XSS) vulnerability affecting cernsearch.web.cern.ch, which at the time of submission ranked 4489 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 19/09/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 16/09/2008 |
Date published: 19/09/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: skathgh420 |
Domain: cernsearch.web.cern.ch |
Category: XSS |
Pagerank: 4489 |
URL: http://cernsearch.web.cern.ch/cernsearch/Default.aspx?query=+The%20CERN%20I%3Cscript%3Ealert(%22iBla ze%22)%3C/script%3Eaassonvert.FromBase64String(String%20s)%20%20%20%20at%20System.Web.UI.ObjectState Formatter.Deserialize(String%20inputString)%20%20%20%20at%20System.Web.UI.ObjectStateFormatter.Syste m.Web.UI.IStateFormatter.Deserialize(String%20serializedState)%20%20%20%20at%20System.Web.UI.Util.De serializeWithAssert(IStateFormatter%20formatter,%20String%20serializedState)%20%20%20%20at%20System. W |
Click here to view the mirror
|
|
|